SUSPICIOUS — xuvurupon.pdf
SUSPICIOUS — xuvurupon.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c8e9359ae7b5d38a64d942b3be81b8d7507089391c812c53ff13ccba079b99c8 - SHA-1:
fcb8708ca10385f0ad41404f78d2282ba477c3fd - MD5:
18455b21f1a70c2c3a92ca67c13fb352 - ssdeep:
768:PgGzpDz+UiIsxMTOG44UTe1O5AKpjkv+1Jz0Z/ecigDQMjBGP6c0JVBeCHz:4GF/71CZKvqz0ZSgDQ8C0PBeCHz - TLSH:
T1BF319EF310ABDC8C7B8ADB23A9A6542D604DD28C6123DBB054DD376CC47C6BDAE10821 - Submitted as: xuvurupon.pdf
- File type: pdf · Size: 42057 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/7b2b8e43-b4e4-4ff1-8f0a-726dd613aa9f/veridian_thermometer_manual.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://traffking.ru/wb?keyword=telephone%20recorder%20app%20iphone, https://cdn-cms.f-static.net/uploads/4373986/normal_5f8da0694a2e3.pdf, https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/wunatotubekarirutaso.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffking.ru/wb?keyword=telephone%20recorder%20app%20iphone
- https://cdn-cms.f-static.net/uploads/4373986/normal_5f8da0694a2e3.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/wunatotubekarirutaso.pdf
- https://cdn-cms.f-static.net/uploads/4368467/normal_5f9b8341866b4.pdf
- https://cdn-cms.f-static.net/uploads/4366400/normal_5fa35943dd575.pdf
- https://cdn-cms.f-static.net/uploads/4366399/normal_5f9f7962e1e86.pdf
- https://s3.amazonaws.com/wonoti/xutowamonodowadomizi.pdf
- https://cdn-cms.f-static.net/uploads/4380695/normal_5f980c19c4270.pdf
- https://cdn-cms.f-static.net/uploads/4443602/normal_5f9d939271782.pdf
- https://zorimogitew.weebly.com/uploads/1/3/4/4/134487520/663b95e9bcbb65.pdf
- https://uploads.strikinglycdn.com/files/7b2b8e43-b4e4-4ff1-8f0a-726dd613aa9f/veridian_thermometer_manual.pdf
- https://cdn-cms.f-static.net/uploads/4417046/normal_5f9d984429a4f.pdf
- https://uploads.strikinglycdn.com/files/e94e6912-db17-4f50-a9b0-77eb39765097/73117270728.pdf
- https://cdn-cms.f-static.net/uploads/4418575/normal_5fa5d8ffb8972.pdf
- https://cdn-cms.f-static.net/uploads/4409610/normal_5f92c5f61fa9d.pdf
- https://cdn-cms.f-static.net/uploads/4387411/normal_5fa284c0ecd03.pdf
- https://cdn-cms.f-static.net/uploads/4413108/normal_5f9c4ef2d2c96.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffking.ru
- cdn-cms.f-static.net
- vozunutav.weebly.com
- s3.amazonaws.com
- zorimogitew.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report