MALICIOUS — dufojateduruxu_molep.pdf
MALICIOUS — dufojateduruxu_molep.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 1 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
32e87200374e4bc2d0068aab353b1378ca2f7fd692b5c75e9bbbe9e6ce2d6fbd - SHA-1:
cb2ca9fdb216c5d699a1d1f84171575a9bb3de85 - MD5:
808752c6fc0822bea33ac5a71c639c40 - ssdeep:
768:hgGzpD7pY5OlkPXgOcxLlDmtYs7nyhlnWfPHvRZeSuWm5KEh07FqAvIc:SGFXpHOU+Y9LnWfPvRXtm5KEhE1vIc - TLSH:
T144316BF740EBDC8C7E869B03ACBB25696486D34C61369790849C777CC4BC6ADAF10960 - Submitted as: dufojateduruxu_molep.pdf
- File type: pdf · Size: 42979 bytes
- Verdict: malicious (71/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/7922058.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=blackpink%20whistle%20mp3%20muzmo, https://papunagaku.weebly.com/uploads/1/3/1/3/131384156/monedivefiz.pdf, https://vibebivenef.weebly.com/uploads/1/3/1/4/131412032/5079214.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=blackpink%20whistle%20mp3%20muzmo
- https://papunagaku.weebly.com/uploads/1/3/1/3/131384156/monedivefiz.pdf
- https://vibebivenef.weebly.com/uploads/1/3/1/4/131412032/5079214.pdf
- https://mogidudurunupiz.weebly.com/uploads/1/3/2/6/132695636/9461a.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/7922058.pdf
- https://tuxitusonodedin.weebly.com/uploads/1/3/0/8/130873989/6693767.pdf
- https://sanuvexugivi.weebly.com/uploads/1/3/1/6/131606490/f981a0edcf09.pdf
- https://togitarusufojir.weebly.com/uploads/1/3/2/6/132681229/boruzigefajuxan.pdf
- https://uploads.strikinglycdn.com/files/c421284f-1598-4ee3-9105-fca0c90e6a1f/gegazom.pdf
- https://uploads.strikinglycdn.com/files/86367ec7-ce87-450e-9071-aaba15290986/10381613076.pdf
- https://uploads.strikinglycdn.com/files/ac8af2f0-5bc8-4e8d-b804-27be898a430d/30230241431.pdf
- https://uploads.strikinglycdn.com/files/cbeff81b-cbe9-46f4-afca-7d5dcb9576a5/wegopuxawadebe.pdf
- https://uploads.strikinglycdn.com/files/178ef1e4-f95a-41aa-af7d-26954aef9411/drake_take_care_torrent.pdf
- https://uploads.strikinglycdn.com/files/30371f05-ba53-461b-bed9-9fafdc8af29d/62823552969.pdf
- https://uploads.strikinglycdn.com/files/00a7dc1a-4e7f-469b-ac04-34a4ace5e96c/pufugepetukefix.pdf
- https://uploads.strikinglycdn.com/files/3b00d10b-1cbd-4c3a-be18-912c8598b794/67869964608.pdf
- https://uploads.strikinglycdn.com/files/05fe0797-179f-46f8-9d69-84de67bb3cd5/68028939484.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/kekikefuwu.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/2122744.pdf
- https://digonowokeke.weebly.com/uploads/1/3/1/8/131856318/newowub-jizerufelaz.pdf
- https://wavuvavezexa.weebly.com/uploads/1/3/0/7/130775629/d670d9a54.pdf
- https://cdn-cms.f-static.net/uploads/4375357/normal_5f8b908944ed7.pdf
- https://cdn-cms.f-static.net/uploads/4372085/normal_5f8a0fc1e995c.pdf
- https://cdn-cms.f-static.net/uploads/4366011/normal_5f8ab737b307f.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f87192989dbf.pdf
Embedded domains
- gettraff.ru
- papunagaku.weebly.com
- vibebivenef.weebly.com
- mogidudurunupiz.weebly.com
- fijojonibiw.weebly.com
- tuxitusonodedin.weebly.com
- sanuvexugivi.weebly.com
- togitarusufojir.weebly.com
- uploads.strikinglycdn.com
- vuxozajuje.weebly.com
- xojerajap.weebly.com
- digonowokeke.weebly.com
- wavuvavezexa.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report