SUSPICIOUS — xovuwez.pdf
SUSPICIOUS — xovuwez.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4e6ac5f6cf2110be70e15900a2ed200c6e5a19ad106d1df9dc7ee6bfcc6d1c22 - SHA-1:
b6f1a4ff0359900cbd691f896c9a375b7c0e919b - MD5:
e42c36ff778915b49093c270008a8117 - ssdeep:
768:egGzpDDpTONZYQDHdyZH64IMqdbSk016qwJz1DieZMEB2:bGFHpTONZxD9yZaJbSZ1Oz1BMEB2 - TLSH:
T13B319EF310E7EC4C7A8BBB539AF61859404AD38C6136A360A99D7B2DC4BC2ED6D10461 - Submitted as: xovuwez.pdf
- File type: pdf · Size: 41509 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/17465c3d-5337-4b02-837f-259e572ccc75/22951999377.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=basic%20excel%20course%20pdf, https://uploads.strikinglycdn.com/files/17465c3d-5337-4b02-837f-259e572ccc75/22951999377.pdf, https://uploads.strikinglycdn.com/files/f4a50f8a-f6bf-4159-8b4e-84be2d48be9a/zupuzoxofozowaga.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=basic%20excel%20course%20pdf
- https://uploads.strikinglycdn.com/files/17465c3d-5337-4b02-837f-259e572ccc75/22951999377.pdf
- https://uploads.strikinglycdn.com/files/f4a50f8a-f6bf-4159-8b4e-84be2d48be9a/zupuzoxofozowaga.pdf
- https://uploads.strikinglycdn.com/files/937b3a0f-2954-46ab-a466-bce3eab7f848/29440853108.pdf
- https://dejolezeg.weebly.com/uploads/1/3/2/8/132815968/tusamuwuto.pdf
- https://uploads.strikinglycdn.com/files/d4b00523-2119-4d4c-8618-2fe4ae7a7a8b/1354923098.pdf
- https://uploads.strikinglycdn.com/files/c8dc4597-e30e-4a26-be72-f8d33796b52d/nuxibojunepekof.pdf
- https://uploads.strikinglycdn.com/files/7f17df4f-fe6b-459f-980e-10426d79ce83/2004_bmw_x5_3.0i_manual.pdf
- https://uploads.strikinglycdn.com/files/7e067b6b-306e-494b-b909-314ba1f9a7f6/64703808859.pdf
- https://uploads.strikinglycdn.com/files/d87da122-4d85-47e1-b771-069a468093e5/majizenezebasula.pdf
- https://uploads.strikinglycdn.com/files/54ceee16-f0af-42d3-8fa4-b68b6eb66ae6/niredivekabodeg.pdf
- https://uploads.strikinglycdn.com/files/71c2c65f-57dc-41de-97e9-56529850c6b5/46419113765.pdf
- https://uploads.strikinglycdn.com/files/96368b0a-a9c0-42c3-a504-3145d039adb7/how_to_clean_keurig_2._0.pdf
- https://uploads.strikinglycdn.com/files/36046bc1-a33d-44ee-9d86-a240650c36ec/vmware_certification_guide.pdf
- https://uploads.strikinglycdn.com/files/85687cfd-338d-4be7-918b-6a1721ee9fc0/26818432461.pdf
- https://uploads.strikinglycdn.com/files/f7fd1859-2aec-4c2e-af9d-81b6181763f4/juwovoka.pdf
- https://uploads.strikinglycdn.com/files/23e5a80c-f4a8-4ee4-9a19-c5f2d546b421/powopa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- dejolezeg.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report