MALICIOUS — xiwelutujekuped.pdf
MALICIOUS — xiwelutujekuped.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
05badd27b739ee9c79c76828f01d4fce33fc1e627d1a3f2d79737e1b1470213d - SHA-1:
943138d98584f3c52a86d60950ceabf2da2ecea4 - MD5:
03bd435ee1b78fff904ceac62a31af36 - ssdeep:
1536:xGF0pEvKIxKk+a4Qh8gcSC1yeHnUdqNAWjq8YVb+:UF0pE9xKA4A8gc91ymUdqN7qXI - TLSH:
T172348DF71087DD4CB68BAB179CBB21AA248EC789513BD7A0548CA72DC47C5AE6E11C10 - Submitted as: xiwelutujekuped.pdf
- File type: pdf · Size: 55502 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://seririgikum.weebly.com/uploads/1/3/0/7/130739922/8811960.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=plantronics%20c054%20headset, https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/b919b1ed8f.pdf, https://seririgikum.weebly.com/uploads/1/3/0/7/130739922/8811960.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=plantronics%20c054%20headset
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/b919b1ed8f.pdf
- https://seririgikum.weebly.com/uploads/1/3/0/7/130739922/8811960.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/kirorafagosox.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/fibaxizimudez.pdf
- https://dagigokes.weebly.com/uploads/1/3/0/7/130739756/49c8f69b631a820.pdf
- https://cdn-cms.f-static.net/uploads/4368243/normal_5f87abdcdc344.pdf
- https://cdn-cms.f-static.net/uploads/4369164/normal_5f87a104bf7fd.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f8761f9e3ebb.pdf
- https://cdn-cms.f-static.net/uploads/4366625/normal_5f873d8a108de.pdf
- https://cdn-cms.f-static.net/uploads/4369141/normal_5f87ad9752e5c.pdf
- https://uploads.strikinglycdn.com/files/e5837e26-afea-4b10-8890-67c0b57bd062/39123857226.pdf
- https://uploads.strikinglycdn.com/files/a22f1c7f-cc8a-4525-af2f-6a7d5fb7ca98/gopigonivi.pdf
- https://uploads.strikinglycdn.com/files/182c4279-a0a9-410c-9d5f-700024094149/94702984958.pdf
- https://uploads.strikinglycdn.com/files/0638a5cd-c9ff-4703-8ab4-706ad7505737/sadinozokiza.pdf
- https://uploads.strikinglycdn.com/files/0f38f12a-6884-4ae2-ae22-791d6c522d80/nudezosalefogerako.pdf
- https://uploads.strikinglycdn.com/files/95c82c5b-4b59-4096-a765-194a30a11bec/wavenepatusu.pdf
- https://uploads.strikinglycdn.com/files/0ace491f-29d7-4bcb-81e6-826fdc90415d/65594611253.pdf
- https://uploads.strikinglycdn.com/files/ab68457d-6e87-473f-8b4c-e04e79735eaa/widurazudux.pdf
- https://cdn-cms.f-static.net/uploads/4366661/normal_5f878cc692d7e.pdf
- https://cdn-cms.f-static.net/uploads/4368486/normal_5f878c5771149.pdf
- https://cdn-cms.f-static.net/uploads/4366401/normal_5f878f2cc27bb.pdf
- https://cdn-cms.f-static.net/uploads/4366628/normal_5f87532402655.pdf
- https://cdn-cms.f-static.net/uploads/4365649/normal_5f8709ea08012.pdf
- https://uploads.strikinglycdn.com/files/54694a92-4b93-4b04-b63c-c0e8ce82c754/mewaravelawezusidigeg.pdf
Embedded domains
- ggtraff.ru
- zoxuzuxebexot.weebly.com
- seririgikum.weebly.com
- gimejexoxixaza.weebly.com
- jakedekokobara.weebly.com
- dagigokes.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report