MALICIOUS — maxawonawamo-rumugedakapasit-zelebawovira.pdf
MALICIOUS — maxawonawamo-rumugedakapasit-zelebawovira.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1f265e39c817fd09239fa08890cc99f9719457c042123d10b0056de675fab404 - SHA-1:
5574f1980ba53c248f86318d93f7bb6b578b7a64 - MD5:
7e80364714170135b3a1d9522ec0f820 - ssdeep:
768:9gGzpDJp4xlZ+cERdvKqNu2DEuBA0onnh4+BzAAI3oTaH3nleqLWfXVY2kw:+GF1pRnNxDEuTKhTk/oTGkqLWve2h - TLSH:
T1F8349EF3109BEC8D7A9E6F036DA7116D518AC78C6127D7A05088763DC1BCAED2F10A61 - Submitted as: maxawonawamo-rumugedakapasit-zelebawovira.pdf
- File type: pdf · Size: 55071 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/belapigojat.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=joker%20soundtrack%202019, https://uploads.strikinglycdn.com/files/1a75049a-44d4-43e1-a24c-6887d62bd8bd/16293624835.pdf, https://uploads.strikinglycdn.com/files/5708ae29-063d-45ca-98be-7c289ad94956/1655230821.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=joker%20soundtrack%202019
- https://uploads.strikinglycdn.com/files/1a75049a-44d4-43e1-a24c-6887d62bd8bd/16293624835.pdf
- https://uploads.strikinglycdn.com/files/5708ae29-063d-45ca-98be-7c289ad94956/1655230821.pdf
- https://uploads.strikinglycdn.com/files/ed40f72d-e7e0-45fc-a7ec-b79be5df440d/rufusazajosidadipitanulub.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/belapigojat.pdf
- https://uploads.strikinglycdn.com/files/7fa96268-3cb0-486c-b64e-4cff4b23cca9/gixasateweweg.pdf
- https://uploads.strikinglycdn.com/files/85d4a6e2-f16e-4f06-9af3-7b2103144d2e/25684912717.pdf
- https://uploads.strikinglycdn.com/files/9b29aceb-7412-4ebb-b655-50f2a81b38b3/53170200420.pdf
- https://uploads.strikinglycdn.com/files/c739e347-6d56-42bf-ac17-be573310fec1/rulomawipivozumaruzemogos.pdf
- https://uploads.strikinglycdn.com/files/3f98f9da-402a-4696-b2e1-193dcfb1ca1d/xumodif.pdf
- https://welavofewefose.weebly.com/uploads/1/3/0/8/130813025/f0e561e.pdf
- https://penulikadima.weebly.com/uploads/1/3/1/4/131482887/e811c8d033370.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/1a27643b41869.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/ratefunerod.pdf
- https://site-1048486.mozfiles.com/files/1048486/dasojuzuxisinebi.pdf
- https://site-1038739.mozfiles.com/files/1038739/39126593364.pdf
- https://site-1037246.mozfiles.com/files/1037246/63997951046.pdf
- https://site-1036685.mozfiles.com/files/1036685/34498784625.pdf
- https://site-1043973.mozfiles.com/files/1043973/vezumobu.pdf
- https://site-1039795.mozfiles.com/files/1039795/nekipisibebab.pdf
- https://site-1039382.mozfiles.com/files/1039382/69307628308.pdf
- https://site-1042548.mozfiles.com/files/1042548/76644835290.pdf
- https://site-1040562.mozfiles.com/files/1040562/sakagogoxuderejiwaxorivo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- guwomenod.weebly.com
- welavofewefose.weebly.com
- penulikadima.weebly.com
- zoxuzuxebexot.weebly.com
- dutitujazekap.weebly.com
- site-1048486.mozfiles.com
- site-1038739.mozfiles.com
- site-1037246.mozfiles.com
- site-1036685.mozfiles.com
- site-1043973.mozfiles.com
- site-1039795.mozfiles.com
- site-1039382.mozfiles.com
- site-1042548.mozfiles.com
- site-1040562.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report