MALICIOUS — fitureji_benonudurivel_vunodekuvos_xapilirav.pdf
MALICIOUS — fitureji_benonudurivel_vunodekuvos_xapilirav.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3795278451cc02a58b2e7929b1f9aee60249af37fe775d70eda87572d3afe455 - SHA-1:
43b8ab6e9b3643ff96f6ddcaf25a26515c79f220 - MD5:
e64a3b188e094f1c9bdf0cd7789dc380 - ssdeep:
1536:1GF9eQXNT2GUXCP/a8pu/xVPoQO39q7eROdn:IF9e8gGUSru/xVP0oyA - TLSH:
T1F434AFF75097DD8C7ACF5F07A9AA01596189D3CC2132D7A01088B77CD5BC9ED2E10A60 - Submitted as: fitureji_benonudurivel_vunodekuvos_xapilirav.pdf
- File type: pdf · Size: 56714 bytes
- Verdict: malicious (75/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/ratot_muweliwamopoj.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=ejemplos%20de%20ensayos%20argumentativos, https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/jogowezokuvaxu.pdf, https://fulipevaxavu.weebly.com/uploads/1/3/2/6/132695351/napofujewub.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=ejemplos%20de%20ensayos%20argumentativos
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/jogowezokuvaxu.pdf
- https://fulipevaxavu.weebly.com/uploads/1/3/2/6/132695351/napofujewub.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/ratot_muweliwamopoj.pdf
- https://femitinekabel.weebly.com/uploads/1/3/1/4/131437683/koduka-manunadiwebawof.pdf
- https://cdn.shopify.com/s/files/1/0266/9468/0775/files/rinazeditefefipid.pdf
- https://cdn.shopify.com/s/files/1/0440/7531/9448/files/karzan_dictionary_mod_apk.pdf
- https://cdn.shopify.com/s/files/1/0428/5962/6655/files/basic_8_trig_identities_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0483/5291/9703/files/wisconsin_medical_license_lookup.pdf
- https://cdn.shopify.com/s/files/1/0430/3876/9303/files/thank_you_emoji_gif.pdf
- https://cdn.shopify.com/s/files/1/0480/4758/7492/files/forerurexeduzapozemid.pdf
- https://cdn.shopify.com/s/files/1/0499/4865/5806/files/97310354336.pdf
- https://cdn.shopify.com/s/files/1/0495/6330/4088/files/lakeland_auto_mall_service_department.pdf
- https://uploads.strikinglycdn.com/files/b27cecfc-b7ed-4f5e-994d-a4672ce83e7e/tamotewotibitapojukul.pdf
- https://uploads.strikinglycdn.com/files/fe1b6072-d0a1-42cd-b568-f0181f2a64d1/rozoxinibimuwez.pdf
- https://uploads.strikinglycdn.com/files/fa3317af-d190-45c1-addf-e2e4d32e3755/puwipisufifuliba.pdf
- https://site-1043694.mozfiles.com/files/1043694/97856358243.pdf
- https://site-1036651.mozfiles.com/files/1036651/fusovos.pdf
- https://site-1041295.mozfiles.com/files/1041295/zuveruzabu.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f8700ee424d5.pdf
- https://cdn-cms.f-static.net/uploads/4365580/normal_5f86f6485e2f7.pdf
- https://cdn-cms.f-static.net/uploads/4365613/normal_5f87174424a10.pdf
- https://cdn-cms.f-static.net/uploads/4365660/normal_5f87052f35163.pdf
- https://cdn-cms.f-static.net/uploads/4367004/normal_5f875f7720199.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- zoxuzuxebexot.weebly.com
- fulipevaxavu.weebly.com
- guwomenod.weebly.com
- femitinekabel.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1043694.mozfiles.com
- site-1036651.mozfiles.com
- site-1041295.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report