SUSPICIOUS — xoviworutu.pdf
SUSPICIOUS — xoviworutu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
b0296096cb8f78feae8396abf7a6d9daf01900c06974c0998b8e5a05823c0a79 - SHA-1:
8bc6cef8faea22e0ce0b2532865b8ca3fc605d5b - MD5:
2ce73b477a1b09e4983c126572f571ad - ssdeep:
1536:tGFLwykMRaC71GLqjFYeHh6sW22oG24m:wFLw/SxhGOjeeB6Ta - TLSH:
T14C35BFF31597EC8C7A86EB039DF625585186C38C607A9BA445CCB72DC4BC7BC6E50860 - Submitted as: xoviworutu.pdf
- File type: pdf · Size: 57602 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=cbse+class+11+physics+textbook+pdf+download, https://site-1037121.mozfiles.com/files/1037121/komogotukizekut.pdf, https://site-1037085.mozfiles.com/files/1037085/gesuraxagewebinagepun.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=cbse+class+11+physics+textbook+pdf+download
- https://site-1037121.mozfiles.com/files/1037121/komogotukizekut.pdf
- https://site-1037085.mozfiles.com/files/1037085/gesuraxagewebinagepun.pdf
- https://site-1036981.mozfiles.com/files/1036981/pidazifi.pdf
- https://site-1036858.mozfiles.com/files/1036858/43750217727.pdf
- https://site-1039274.mozfiles.com/files/1039274/85392857351.pdf
- https://uploads.strikinglycdn.com/files/ffdf3f95-3f2c-45d4-9121-8d334f039b2e/lamejabixadimunabanim.pdf
- https://uploads.strikinglycdn.com/files/dff95ada-a360-4683-981d-4e04ba1a3982/gezezorosiponizugened.pdf
- https://uploads.strikinglycdn.com/files/5a32e20a-e0ca-4ba9-b14b-525741cb56b7/kalob.pdf
- https://uploads.strikinglycdn.com/files/3d273d84-c06d-47c4-8552-f8affee1cbbf/59449606713.pdf
- https://uploads.strikinglycdn.com/files/8bc0c6a4-626c-49cd-9e06-04846b81d2fa/musekazemirumuwigadune.pdf
- https://uploads.strikinglycdn.com/files/799e1017-c0d9-47db-bd89-5e274f24ce95/353693941.pdf
- https://uploads.strikinglycdn.com/files/75110744-9aba-4454-a8b9-7774babbc8a1/wavemeluzo.pdf
- https://uploads.strikinglycdn.com/files/9a2df8ff-ff06-4d54-8798-66fb7dd71080/wipilemurulolovosetawo.pdf
- https://uploads.strikinglycdn.com/files/c9dfaa28-9367-4525-bae8-a70b5e8f79f0/derajuzalevedepavive.pdf
- https://uploads.strikinglycdn.com/files/db84b7d3-1f63-4ffd-95eb-9e89edb0cc26/37740884993.pdf
- https://uploads.strikinglycdn.com/files/e34eebdc-a991-42da-8fdf-5f415b8c0b6c/53650385219.pdf
- https://uploads.strikinglycdn.com/files/3f6e263c-7c32-4e35-b184-a7850e6dae7f/26477883701.pdf
- https://uploads.strikinglycdn.com/files/a8a88340-76de-403a-9c10-c0a70c93a81a/31853306829.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1037121.mozfiles.com
- site-1037085.mozfiles.com
- site-1036981.mozfiles.com
- site-1036858.mozfiles.com
- site-1039274.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report