MALICIOUS — xowevekufiserur.pdf
MALICIOUS — xowevekufiserur.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
35e3d85f8abb0ba67f1521c5ba80dd20deb96bb8bf66c6e734bfe9ce818b1330 - SHA-1:
aaa1398866d989425f4e873faf9b111abdd5eeb8 - MD5:
7425b808aad5d2851bc73bfae3436796 - ssdeep:
768:ngGzpDRpT97RoHaWVz65/Gc98OY0mXnIqOP0fArkI2Rosak//lcz9e8lrO4C5E:gGFNpT/+ovmXn/ArkI4osj/KLlrnC5E - TLSH:
T105328DF320A7EC8C7E8BBB07ADB614A4208AC7486137D79159887B2DD4BC5BD7E01560 - Submitted as: xowevekufiserur.pdf
- File type: pdf · Size: 45777 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/76c30d49.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=essential%20oil%20chart, https://cdn-cms.f-static.net/uploads/4366348/normal_5f87687d8e32d.pdf, https://cdn-cms.f-static.net/uploads/4369504/normal_5f87cfab231b7.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=essential%20oil%20chart
- https://cdn-cms.f-static.net/uploads/4366348/normal_5f87687d8e32d.pdf
- https://cdn-cms.f-static.net/uploads/4369504/normal_5f87cfab231b7.pdf
- https://cdn-cms.f-static.net/uploads/4367947/normal_5f8790cbd6cab.pdf
- https://mamexobupelo.weebly.com/uploads/1/3/1/3/131383482/fakufofawitowidera.pdf
- https://gukepofefefika.weebly.com/uploads/1/3/1/4/131437977/kisukipuxusukemu.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/76c30d49.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/metor.pdf
- https://site-1042009.mozfiles.com/files/1042009/tubus.pdf
- https://site-1039378.mozfiles.com/files/1039378/rovifogepobu.pdf
- https://site-1043400.mozfiles.com/files/1043400/64037439214.pdf
- https://site-1043095.mozfiles.com/files/1043095/46102829786.pdf
- https://uploads.strikinglycdn.com/files/35a737e9-9783-4ca3-95e3-3cf09fc94857/74180639915.pdf
- https://uploads.strikinglycdn.com/files/b1181324-625a-41ca-ba98-bd59718d63dc/87212586290.pdf
- https://uploads.strikinglycdn.com/files/8f2400c3-42b9-4d97-85cc-1d5580b5caff/20711659761.pdf
- https://uploads.strikinglycdn.com/files/da6a48c4-a417-4302-bbf4-f317ac9eba86/64902453806.pdf
- https://uploads.strikinglycdn.com/files/31252676-0ea2-4e02-a9b9-13b75c5eb97c/kosuxejulazovogemo.pdf
- https://uploads.strikinglycdn.com/files/23eb039e-d4a4-4d57-b036-ffa9e9001fda/26404776128.pdf
- https://uploads.strikinglycdn.com/files/5ea63110-afc7-41bc-9264-0e96c64d80e5/zukegopifadigafepexemur.pdf
- https://cdn-cms.f-static.net/uploads/4366398/normal_5f874a15253ac.pdf
- https://cdn-cms.f-static.net/uploads/4366952/normal_5f876f57ca5f9.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f87009971421.pdf
- https://cdn-cms.f-static.net/uploads/4368487/normal_5f8786d087615.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- mamexobupelo.weebly.com
- gukepofefefika.weebly.com
- dutitujazekap.weebly.com
- zoxuzuxebexot.weebly.com
- site-1042009.mozfiles.com
- site-1039378.mozfiles.com
- site-1043400.mozfiles.com
- site-1043095.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report