SUSPICIOUS — lixasog.pdf
SUSPICIOUS — lixasog.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bf36c2791bccbb6d88ff1760d79ffeb9037e9b8b8e0dae8e64195e1de2970549 - SHA-1:
9d58ee23f6c05abf966b967246757f004d9f9429 - MD5:
45ea253edabd326213668cbb978e7f5a - ssdeep:
768:PgGzpDCpXo56t9Jjr9M09+VMd1HKn9PXyvCon7K:4GFOd9Jjr96Vq1g9PFon7K - TLSH:
T159308CF34497ED8C7A8BA703A9B210695188D749A137CB6018DC777CC4BC6BDAF518A0 - Submitted as: lixasog.pdf
- File type: pdf · Size: 38290 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.kcpsychologist.com/uploads/1/3/1/3/131379591/zokuredaxira.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=toefl+answer+sheet+pdf, http://files.skylercoleallen.com/uploads/1/3/0/7/130740256/wawirupa-wugolibiwulagu-takur.pdf, http://files.saveekuriforest.com/uploads/1/3/0/8/130813887/tafofileparazum-xijalewinadof-jesenejopixuw.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=toefl+answer+sheet+pdf
- http://files.skylercoleallen.com/uploads/1/3/0/7/130740256/wawirupa-wugolibiwulagu-takur.pdf
- http://files.saveekuriforest.com/uploads/1/3/0/8/130813887/tafofileparazum-xijalewinadof-jesenejopixuw.pdf
- http://varuwut.blueridgepac.net/uploads/1/3/1/8/131856293/pewerorazotad.pdf
- http://wusos.ashlynnsboutique.com/uploads/1/3/1/4/131437594/tuganixesifatur.pdf
- http://files.phoenixphusion.com/uploads/1/3/1/4/131406662/58be7.pdf
- http://files.kcpsychologist.com/uploads/1/3/1/3/131379591/zokuredaxira.pdf
- http://faripit.thesacredactor.com/uploads/1/3/1/4/131408168/5668303.pdf
- http://sosibagu.mydigitalhandprint.com/uploads/1/3/2/8/132814989/49517d1d807b9d.pdf
- http://files.howemtnknives.com/uploads/1/3/2/8/132814967/kemagebogilis-kijurapeji-mobit.pdf
- http://files.suehuitt.com/uploads/1/3/2/6/132695321/1357547.pdf
- https://uploads.strikinglycdn.com/files/c1b7f9ae-098f-485a-9f36-70bf55c6b8e8/tabamikebu.pdf
- https://uploads.strikinglycdn.com/files/2a862c68-0d90-4e95-8acc-0b92cfb646a2/99814396449.pdf
- https://uploads.strikinglycdn.com/files/4bcd830f-607e-49c0-b458-915e278eaf97/namadefosamemabad.pdf
- https://uploads.strikinglycdn.com/files/7ffc260d-a8e5-4a48-b66b-97839f41200f/87168053678.pdf
- https://cdn.shopify.com/s/files/1/0433/5039/2984/files/81615402910.pdf
- https://cdn.shopify.com/s/files/1/0433/5517/7109/files/divine_sorcerer_5e_guide.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.skylercoleallen.com
- files.saveekuriforest.com
- varuwut.blueridgepac.net
- wusos.ashlynnsboutique.com
- files.phoenixphusion.com
- files.kcpsychologist.com
- faripit.thesacredactor.com
- sosibagu.mydigitalhandprint.com
- files.howemtnknives.com
- files.suehuitt.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report