SUSPICIOUS — xerexazewori.pdf
SUSPICIOUS — xerexazewori.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
23952ef7ef460eaa3fef3b50193a77e3dcfa53a554c106f5445d6066168c0aaa - SHA-1:
01b803243cb176f3a0ca4ba1df0448c69d04094f - MD5:
273d345b2772d393091e0faf86114b18 - ssdeep:
768:0gGzpD00x45X5KSPwVEqIUsIjn/4mdj7ggSEwY5XaBCCzeDn:BGFYbUFhdjsgS+qBCCzeDn - TLSH:
T13F318EF39097DD4D7A8BEB13AEB6245C5149C78C6032A7B018983B6CC4BC6BD6E50960 - Submitted as: xerexazewori.pdf
- File type: pdf · Size: 40562 bytes
- Verdict: suspicious (58/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/151a64ea-9a8e-4d2b-9b49-d321e99d7c86/nalodebidofomegepux.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://trafficel.ru/wb?keyword=executive%20summary%20examples%20research, https://cdn-cms.f-static.net/uploads/4367916/normal_5f92e4188f7d1.pdf, https://uploads.strikinglycdn.com/files/151a64ea-9a8e-4d2b-9b49-d321e99d7c86/nalodebidofomegepux.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafficel.ru/wb?keyword=executive%20summary%20examples%20research
- https://s3.amazonaws.com/bejenosugede/merozerovipulamigagikimed.pdf
- https://cdn-cms.f-static.net/uploads/4367916/normal_5f92e4188f7d1.pdf
- https://uploads.strikinglycdn.com/files/151a64ea-9a8e-4d2b-9b49-d321e99d7c86/nalodebidofomegepux.pdf
- https://s3.amazonaws.com/zijivevip/basadoziwidir.pdf
- https://s3.amazonaws.com/fakuguvil/16220777124.pdf
- https://s3.amazonaws.com/vunizi/negelowuxuxe.pdf
- https://uploads.strikinglycdn.com/files/7dfd46a9-e07b-4ade-b0ef-98cc4bbe0ea6/jefutumud.pdf
- https://uploads.strikinglycdn.com/files/131e49b4-5e32-45ad-8031-a9c967f7c3b1/73104706625.pdf
- https://s3.amazonaws.com/leguvefu/woxovexuxaluse.pdf
- https://uploads.strikinglycdn.com/files/cb21b754-70ad-4657-b06e-2fc7f1a32786/nodorunowupug.pdf
- https://cdn-cms.f-static.net/uploads/4368731/normal_5f9e6b56dfa68.pdf
- https://s3.amazonaws.com/muvemasoxaji/fundamentals_of_physical_chemistry.pdf
- https://uploads.strikinglycdn.com/files/4073c4bc-3d01-4ad2-9b4b-a5a99c3c5768/kaiser_permanente_summer_internship_2018.pdf
- https://cdn.shopify.com/s/files/1/0436/9301/5190/files/integrated_1_answers.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafficel.ru
- s3.amazonaws.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report