MALICIOUS — tuwewalovirozul.pdf
MALICIOUS — tuwewalovirozul.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0081a6f4126b394c5fe0897d7ef75eb43bfeb7747988a63cc18da037a9d8945f - SHA-1:
257b58ed27b96df149d314776fd705ecaa9989b5 - MD5:
ab78375b50e65d8f379cf85ddb5c8069 - ssdeep:
768:cgGzpD7prCV31LUrUv84QdSwJycah1x1Vf9MA30F:5GFnpPgwJycah1xLf9R30F - TLSH:
T160328DF710A7EC4CFA8F6B039EAB10DA508AD78D513797A044DC672DC17C2AD6E50920 - Submitted as: tuwewalovirozul.pdf
- File type: pdf · Size: 46813 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/7749793.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=haritaki%20health%20benefits, https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/7749793.pdf, https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/vunidixeviro_xitosujitupile_kadape.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=haritaki%20health%20benefits
- https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/7749793.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/vunidixeviro_xitosujitupile_kadape.pdf
- https://xuwuperozaposa.weebly.com/uploads/1/3/2/3/132303395/dd7811.pdf
- https://kufazijofiw.weebly.com/uploads/1/3/0/7/130776126/7585037.pdf
- https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/tukeduzirejubagum.pdf
- https://rajomiluti.weebly.com/uploads/1/3/2/6/132682989/xuzulokijifefevuxa.pdf
- https://riragojefo.weebly.com/uploads/1/3/1/8/131857115/tosudovenagivaj-ridof-voxupin.pdf
- https://jemiwuwavaza.weebly.com/uploads/1/3/0/8/130814288/tigosorivibisakoxu.pdf
- https://fusesekomufe.weebly.com/uploads/1/3/1/6/131606177/41276293.pdf
- https://site-1044303.mozfiles.com/files/1044303/76030129368.pdf
- https://site-1038358.mozfiles.com/files/1038358/befidasawipokujesu.pdf
- https://site-1043471.mozfiles.com/files/1043471/susalemu.pdf
- https://site-1038836.mozfiles.com/files/1038836/76499651197.pdf
- https://site-1043879.mozfiles.com/files/1043879/44944832386.pdf
- https://site-1041372.mozfiles.com/files/1041372/nuevo_android_auto_beta.pdf
- https://site-1042832.mozfiles.com/files/1042832/cpu_z_apk_free_download.pdf
- https://site-1037073.mozfiles.com/files/1037073/94293281995.pdf
- https://uploads.strikinglycdn.com/files/6736c11f-4025-4e7b-8e53-7c9d33708473/99010216836.pdf
- https://uploads.strikinglycdn.com/files/6991d0d2-9f3f-406e-8b86-fc65a2cbd327/zezabakoxapazinujexiw.pdf
- https://uploads.strikinglycdn.com/files/c290b69c-3c19-470c-ae2b-a37922dd2779/54503671670.pdf
- https://uploads.strikinglycdn.com/files/02670cc1-b64d-4023-8887-e1b9e32957dd/mojoloxuzajukat.pdf
- https://cdn-cms.f-static.net/uploads/4368488/normal_5f8898f85167f.pdf
- https://cdn-cms.f-static.net/uploads/4366627/normal_5f875e6737e56.pdf
- https://cdn-cms.f-static.net/uploads/4369630/normal_5f88c618590fc.pdf
Embedded domains
- cctraff.ru
- kabudededawizo.weebly.com
- bedizegoresupa.weebly.com
- xuwuperozaposa.weebly.com
- kufazijofiw.weebly.com
- fodezamu.weebly.com
- rajomiluti.weebly.com
- riragojefo.weebly.com
- jemiwuwavaza.weebly.com
- fusesekomufe.weebly.com
- site-1044303.mozfiles.com
- site-1038358.mozfiles.com
- site-1043471.mozfiles.com
- site-1038836.mozfiles.com
- site-1043879.mozfiles.com
- site-1041372.mozfiles.com
- site-1042832.mozfiles.com
- site-1037073.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report