MALICIOUS — xutagakal.pdf
MALICIOUS — xutagakal.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2c150ded8d9808ff6d86f86213ac0930cb042a3bc6ca39ddfd904d8b902d0c3f - SHA-1:
130ad3c931ccbd1ead0f116f7633da24720d8e9d - MD5:
4c2bc03be5004aa437896a4b7df56624 - ssdeep:
1536:IGFDpQqmHajZwVr7LlU96Yvh2PGWVUsyyyBEkuT:lFDpQqJazls682PTU5ylku - TLSH:
T176338DF710E3DE8C3A87AF4399FB12A6A085D389712A87904488776CD07C5FC6F51960 - Submitted as: xutagakal.pdf
- File type: pdf · Size: 51031 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/debizikirapanas.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=maths%20worksheets%20for%20grade%206%20ratio%20and%20proportion, https://uploads.strikinglycdn.com/files/3f4d7aed-684a-4779-adfb-43c3568414e2/zoxevofexano.pdf, https://uploads.strikinglycdn.com/files/c2ee439f-5529-485b-a4a0-6ff1fef2cc76/14114090360.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=maths%20worksheets%20for%20grade%206%20ratio%20and%20proportion
- https://uploads.strikinglycdn.com/files/3f4d7aed-684a-4779-adfb-43c3568414e2/zoxevofexano.pdf
- https://uploads.strikinglycdn.com/files/c2ee439f-5529-485b-a4a0-6ff1fef2cc76/14114090360.pdf
- https://uploads.strikinglycdn.com/files/3281c34c-b12a-482e-9bb2-bb379631a724/islas_para_centros_comerciales.pdf
- https://uploads.strikinglycdn.com/files/459e008c-0398-4a65-8ce4-4c999e8e7490/vinokivuvudugiden.pdf
- https://zoveponezewuda.weebly.com/uploads/1/3/0/7/130738822/3d7af44.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/debizikirapanas.pdf
- https://uploads.strikinglycdn.com/files/9dd35a55-3061-43d0-8072-be265d9a4be5/dragon_quest_11_strategy_guide_prima.pdf
- https://uploads.strikinglycdn.com/files/3e126f4c-eb60-4d98-b5d4-24c4af49b0d6/77296904156.pdf
- https://xoraxabaxid.weebly.com/uploads/1/3/2/6/132682630/goxodoxogeguboz_zofores_zenikafozovi_bisuxomularoxan.pdf
- https://wefejakero.weebly.com/uploads/1/3/0/8/130814310/1524667.pdf
- https://xawuwotogot.weebly.com/uploads/1/3/2/6/132695388/8933243.pdf
- https://nudopimiga.weebly.com/uploads/1/3/1/0/131070212/kevojijo_mizimaperijoji_tusamuxugajela_wegivixojime.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/1158663.pdf
- https://cdn-cms.f-static.net/uploads/4375210/normal_5f8d1cbb7df63.pdf
- https://cdn-cms.f-static.net/uploads/4369494/normal_5f90395894951.pdf
- https://cdn-cms.f-static.net/uploads/4365562/normal_5f9159e2501c3.pdf
- https://cdn-cms.f-static.net/uploads/4379837/normal_5f8fc802cb698.pdf
- https://cdn.shopify.com/s/files/1/0500/0436/1366/files/riley_inside_out_hockey.pdf
- https://cdn.shopify.com/s/files/1/0431/3487/7853/files/bojozobevofozu.pdf
- https://cdn.shopify.com/s/files/1/0435/4179/0871/files/xosipitakulupawoduna.pdf
- https://cdn.shopify.com/s/files/1/0499/3282/8824/files/kinamufepezekikuk.pdf
- https://cdn.shopify.com/s/files/1/0476/7806/2758/files/china_environmental_issues.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- zoveponezewuda.weebly.com
- vuxozajuje.weebly.com
- xoraxabaxid.weebly.com
- wefejakero.weebly.com
- xawuwotogot.weebly.com
- nudopimiga.weebly.com
- dutitujazekap.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report