SUSPICIOUS — zenurivixiwewoxirisezi.pdf
SUSPICIOUS — zenurivixiwewoxirisezi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
848b34c728f72789f7861a206b4472ffc3d65fb0aacab387f0c3a051eb4aaab9 - SHA-1:
aae3b85cd3fcfcb8199fdc0e09ecc0df9e93190c - MD5:
395ef482957d22188bcb6bbbae8382e1 - ssdeep:
768:igGzpDMUNTcju5fTXmICfhtSlozQ/YrFXRBOJoh:/GFwi15fqIxYZXRBOJoh - TLSH:
T1CA318DF750A7DE4C79C36B83ACA61599508AD3887223B3A045D87B2D80B81BDBF41D61 - Submitted as: zenurivixiwewoxirisezi.pdf
- File type: pdf · Size: 42801 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/dc336f04-d6c4-4cbb-b7ee-6d3ac682b8fb/89802269303.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=clasificaci%25C3%25B3n+de+los+actos+de+comercio+pdf, https://site-1036630.mozfiles.com/files/1036630/zululasukezomonafu.pdf, https://site-1036920.mozfiles.com/files/1036920/xokixev.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=clasificaci%25C3%25B3n+de+los+actos+de+comercio+pdf
- https://site-1036630.mozfiles.com/files/1036630/zululasukezomonafu.pdf
- https://site-1036920.mozfiles.com/files/1036920/xokixev.pdf
- https://site-1038467.mozfiles.com/files/1038467/24412790662.pdf
- https://site-1036925.mozfiles.com/files/1036925/20165722085.pdf
- https://site-1037169.mozfiles.com/files/1037169/tasinewonadujinone.pdf
- https://uploads.strikinglycdn.com/files/dc336f04-d6c4-4cbb-b7ee-6d3ac682b8fb/89802269303.pdf
- https://uploads.strikinglycdn.com/files/66b3a969-e0e3-4b11-92b5-f1c5ab649d95/tigefi.pdf
- https://uploads.strikinglycdn.com/files/c79e08bd-e59c-45c4-afb2-995bfae733c3/47612886424.pdf
- https://site-1036728.mozfiles.com/files/1036728/38713407682.pdf
- https://site-1036988.mozfiles.com/files/1036988/61740812187.pdf
- https://site-1037079.mozfiles.com/files/1037079/53514220792.pdf
- https://uploads.strikinglycdn.com/files/96e83afc-9b36-4bba-8afd-10421a47e3eb/siwumafadu.pdf
- https://uploads.strikinglycdn.com/files/ca50266b-127e-4599-928b-c26910b69ee3/jaxolemoxoxukuto.pdf
- https://uploads.strikinglycdn.com/files/b6eff01b-03ce-4970-8bee-05ec8de54039/bokulaz.pdf
- https://uploads.strikinglycdn.com/files/80c7e17a-8c47-4cc5-bb51-324ae32069ab/kivipameworuwesetetu.pdf
- https://uploads.strikinglycdn.com/files/b83abd75-e836-4ee2-b5e4-9835f0df6afd/74026222413.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1036630.mozfiles.com
- site-1036920.mozfiles.com
- site-1038467.mozfiles.com
- site-1036925.mozfiles.com
- site-1037169.mozfiles.com
- uploads.strikinglycdn.com
- site-1036728.mozfiles.com
- site-1036988.mozfiles.com
- site-1037079.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report