MALICIOUS — kazopasaw-nuzod.pdf
MALICIOUS — kazopasaw-nuzod.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2de9699f8ec346a797e4218a7f08ed4695e9ab20baf09979dd38a0a4c53d0719 - SHA-1:
293fffcd5a85ea6a63651cf4086bdab1d73f360b - MD5:
adb38190b96f21022427ae6a2fbbd7c7 - ssdeep:
1536:AGFDe1zuvCNJrL3hUgXPnbezsBzcEl38KdOgf6j7:NFDe1zuqTrWgfbWsBzjlMoOwS - TLSH:
T1F737D0F3505BEC8CB78BAF036AFA1059658ED7082032EB584599B72CC87C67D6E50E50 - Submitted as: kazopasaw-nuzod.pdf
- File type: pdf · Size: 72563 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/b4b3eb38b.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=marvel%20vs%20capcom%203%20unlockable%20characters, https://uploads.strikinglycdn.com/files/b4da4455-a74a-4c0d-8735-6356eaebe7c6/81246963444.pdf, https://uploads.strikinglycdn.com/files/65788016-66d0-4a48-944f-219fe556e9b9/morumuvixaxuja.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=marvel%20vs%20capcom%203%20unlockable%20characters
- https://uploads.strikinglycdn.com/files/b4da4455-a74a-4c0d-8735-6356eaebe7c6/81246963444.pdf
- https://uploads.strikinglycdn.com/files/65788016-66d0-4a48-944f-219fe556e9b9/morumuvixaxuja.pdf
- https://uploads.strikinglycdn.com/files/516e211d-eedd-47fc-a7bd-ce94208a0bd6/38129368582.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/b4b3eb38b.pdf
- https://wekubuzebebam.weebly.com/uploads/1/3/0/7/130739705/8689160.pdf
- https://ninukiwipovesot.weebly.com/uploads/1/3/0/9/130969879/bdbc33bd.pdf
- https://fifowekuvepu.weebly.com/uploads/1/3/0/7/130776735/9949725.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/40ddfa4d7f4e3e.pdf
- https://uploads.strikinglycdn.com/files/dc11ef5d-5579-4e44-aae1-80706337e17a/xapubisefed.pdf
- https://uploads.strikinglycdn.com/files/47fe3fd1-d9c7-4c6a-9ecc-0a2d6e1dc817/89404239496.pdf
- https://uploads.strikinglycdn.com/files/d59829b9-49b5-495c-9578-800700b77aa4/36681644619.pdf
- https://uploads.strikinglycdn.com/files/2482e24a-eb26-4eb0-9b3d-e33ab0f1a803/najotolunujerul.pdf
- https://uploads.strikinglycdn.com/files/a0db2999-4d3e-463b-b98f-00a6a6782146/vubori.pdf
- https://sakuvida.weebly.com/uploads/1/3/0/7/130775714/8693383.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/rotizizalipi-xulejowo-wegevok-xutijub.pdf
- https://site-1039809.mozfiles.com/files/1039809/ropelebazirif.pdf
- https://site-1039633.mozfiles.com/files/1039633/68054693274.pdf
- https://uploads.strikinglycdn.com/files/e691a531-e514-48a6-9da4-f2dc66c62967/19763287846.pdf
- https://uploads.strikinglycdn.com/files/451738b0-0478-481c-aa06-8f54fc5da168/jutevogalalidexusi.pdf
- https://uploads.strikinglycdn.com/files/9b9213a3-1c84-4349-8bfe-5f819f960c31/guvunapezomigigiwokufu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- gimejexoxixaza.weebly.com
- wekubuzebebam.weebly.com
- ninukiwipovesot.weebly.com
- fifowekuvepu.weebly.com
- mogilifus.weebly.com
- sakuvida.weebly.com
- fijojonibiw.weebly.com
- site-1039809.mozfiles.com
- site-1039633.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report