MALICIOUS — xovuseka.pdf
MALICIOUS — xovuseka.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2ca18260e8c5ab813f29b26a373578416eea2a7efefb04dfcbb71e14eb7ec122 - SHA-1:
7670f248cf16b41d5b47c62f22f70cd32c1ca778 - MD5:
12eb97194c566d95a33d7a8e263d515c - ssdeep:
1536:vGFWe65YklryOa2R7XYJE98edRYlKkop:eFWeV4eO1XYJq7YlA - TLSH:
T1EB338EF750A3ED4C7A8BE7539DAB109A248AD3486277D3A04498B73CC47C2ADBF11950 - Submitted as: xovuseka.pdf
- File type: pdf · Size: 50260 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/rebodi.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=the%20prox%20transmission, https://site-1040575.mozfiles.com/files/1040575/seranamide.pdf, https://site-1043335.mozfiles.com/files/1043335/veromiduti.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=the%20prox%20transmission
- https://site-1040575.mozfiles.com/files/1040575/seranamide.pdf
- https://site-1043335.mozfiles.com/files/1043335/veromiduti.pdf
- https://site-1041934.mozfiles.com/files/1041934/57590792501.pdf
- https://site-1039149.mozfiles.com/files/1039149/84309959043.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/rebodi.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/pokobu-pidoror-pekirez.pdf
- https://fanavepuru.weebly.com/uploads/1/3/1/8/131871984/e7d349a668e.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/xizaxamuxive.pdf
- https://gemaxudemaxepeb.weebly.com/uploads/1/3/1/0/131070646/1f2f042291555f9.pdf
- https://vopevejefed.weebly.com/uploads/1/3/1/6/131606133/widipumov.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/vigirupiruwovilav.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/gosibokuvefuj.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/613a711ec7ef.pdf
- https://uploads.strikinglycdn.com/files/ea25569d-e6f5-4c2b-9240-4c65a462ffa0/2671256089.pdf
- https://uploads.strikinglycdn.com/files/881cb7ca-1149-4fc9-957d-f8560edfcdad/kogumesijemitabofijomel.pdf
- https://uploads.strikinglycdn.com/files/a5e43f27-1fe0-40b8-92da-b3024b770baa/80351012412.pdf
- https://site-1044455.mozfiles.com/files/1044455/deledulidur.pdf
- https://site-1048568.mozfiles.com/files/1048568/tifalowigurovevoledidat.pdf
- https://uploads.strikinglycdn.com/files/3e581fa9-a0ca-4694-8775-0e345120dab3/daden.pdf
- https://uploads.strikinglycdn.com/files/ae40c6b2-43f9-4a7d-8068-e2dbcb4d67c2/83089256293.pdf
- https://uploads.strikinglycdn.com/files/111ed8f1-1708-40e1-9063-7b77d0a2c36f/44870351116.pdf
- https://uploads.strikinglycdn.com/files/cfce034b-c647-4e4b-b7f9-2acddab7db87/zurewewalovujudotutukor.pdf
- https://uploads.strikinglycdn.com/files/48861aaf-555a-40e1-93c5-8a09bd78be73/nujiturodizu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- site-1040575.mozfiles.com
- site-1043335.mozfiles.com
- site-1041934.mozfiles.com
- site-1039149.mozfiles.com
- jatorogerujew.weebly.com
- zoxuzuxebexot.weebly.com
- fanavepuru.weebly.com
- dutitujazekap.weebly.com
- gemaxudemaxepeb.weebly.com
- vopevejefed.weebly.com
- keniwuki.weebly.com
- fijojonibiw.weebly.com
- uploads.strikinglycdn.com
- site-1044455.mozfiles.com
- site-1048568.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report