SUSPICIOUS — xovezofawinip.pdf
SUSPICIOUS — xovezofawinip.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a630eff4f575e9dd4a50d5a28755759a48f583c04bea4a9e3696d5af260a4ffa - SHA-1:
fef4f72c113d52705c20bb341e040caa341c24d3 - MD5:
0e3657ba80b5f2f402798168b6ecc06a - ssdeep:
1536:XGFqEXe3+icaiXdhHtGwvWFXPcnFNKX5:2Fq1+iItVt5KUnbKp - TLSH:
T1CC33AEF351ABED8C6A96A703ACEA15496645C38C3133E76015C8677DC8BC6FCAE10970 - Submitted as: xovezofawinip.pdf
- File type: pdf · Size: 51308 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/f9c7c166-a5f3-439c-ba7f-2185bf99046c/xuditewokexafo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=phasor+algebra+pdf, http://files.pomeroyshpe.com/uploads/1/3/2/7/132740384/xidovojomolinam.pdf, http://files.rgvmenu.com/uploads/1/3/0/8/130873921/2746372.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=phasor+algebra+pdf
- http://files.pomeroyshpe.com/uploads/1/3/2/7/132740384/xidovojomolinam.pdf
- http://files.rgvmenu.com/uploads/1/3/0/8/130873921/2746372.pdf
- http://puditefa.lourrylegarde.com/uploads/1/3/1/6/131637814/a6728f7494.pdf
- https://site-1041672.mozfiles.com/files/1041672/65793789825.pdf
- https://site-1040282.mozfiles.com/files/1040282/rebudipe.pdf
- https://uploads.strikinglycdn.com/files/f9c7c166-a5f3-439c-ba7f-2185bf99046c/xuditewokexafo.pdf
- https://uploads.strikinglycdn.com/files/aaabdb3c-ea6e-4472-a3af-ffd3e6ef3762/50561044552.pdf
- https://uploads.strikinglycdn.com/files/adde983a-4127-45f8-8a24-4d899e3979e2/bupugenupoza.pdf
- https://uploads.strikinglycdn.com/files/4b6a1eaa-e7b6-498b-b3d3-f6b6b935b327/xopibarejubimalodutedu.pdf
- https://uploads.strikinglycdn.com/files/cedb8eb6-39d2-4ccf-99a8-c41e65776961/zidiga.pdf
- https://cdn.shopify.com/s/files/1/0482/9315/0875/files/7569969894.pdf
- https://cdn.shopify.com/s/files/1/0498/4579/7026/files/25413201302.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.pomeroyshpe.com
- files.rgvmenu.com
- puditefa.lourrylegarde.com
- site-1041672.mozfiles.com
- site-1040282.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report