SUSPICIOUS — xovex.pdf
SUSPICIOUS — xovex.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
6909a65c885610f9efe7bbb0c190fe794bb5549eabb8db51584166fc99326c0d - SHA-1:
c7e2f3ff37963fda42c12ba4868b0363da9de38d - MD5:
31ae04e1f3f6a457ac92f4a6175b8856 - ssdeep:
768:jgGzpDI4FMPLfeNPE0iRkjrV+E/TwrOO3Y:cGFUnea0nsOiOO3Y - TLSH:
T1CF307CF354A3ED8CBACBAB079CEA1045954AC7886133E7605899376DD0BC67DBF00960 - Submitted as: xovex.pdf
- File type: pdf · Size: 35799 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=black+angus+dinner+menu+pdf, https://site-1036646.mozfiles.com/files/1036646/42611103466.pdf, https://site-1037189.mozfiles.com/files/1037189/96213271175.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=black+angus+dinner+menu+pdf
- https://site-1036646.mozfiles.com/files/1036646/42611103466.pdf
- https://site-1037189.mozfiles.com/files/1037189/96213271175.pdf
- https://site-1036779.mozfiles.com/files/1036779/dexoz.pdf
- https://site-1036946.mozfiles.com/files/1036946/96053620319.pdf
- https://site-1037166.mozfiles.com/files/1037166/58204611885.pdf
- https://site-1036733.mozfiles.com/files/1036733/labevijigof.pdf
- https://site-1037222.mozfiles.com/files/1037222/36994105853.pdf
- https://site-1037113.mozfiles.com/files/1037113/18363156435.pdf
- https://site-1036879.mozfiles.com/files/1036879/15498393686.pdf
- https://site-1037125.mozfiles.com/files/1037125/gajexujedegiloxolag.pdf
- https://uploads.strikinglycdn.com/files/1d5a9fa1-4729-48ff-be03-76a8cd231a9a/banenigamerelutep.pdf
- https://uploads.strikinglycdn.com/files/e8403ab1-200f-40f2-9d1d-43f4537493f7/81467524526.pdf
- https://uploads.strikinglycdn.com/files/06806366-31ea-4ecc-a45a-7d967fef1269/tixax.pdf
- https://uploads.strikinglycdn.com/files/0b2a8a3c-ceee-4650-ba95-b6601a961741/2674919618.pdf
- https://uploads.strikinglycdn.com/files/83010f43-3822-46b8-8114-cf210524dd80/25238658565.pdf
- https://uploads.strikinglycdn.com/files/8a9a2823-51aa-41f0-8ef7-0ec8dbf46882/lurixibumisoximexejekig.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1036646.mozfiles.com
- site-1037189.mozfiles.com
- site-1036779.mozfiles.com
- site-1036946.mozfiles.com
- site-1037166.mozfiles.com
- site-1036733.mozfiles.com
- site-1037222.mozfiles.com
- site-1037113.mozfiles.com
- site-1036879.mozfiles.com
- site-1037125.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report