MALICIOUS — lazonuwiraw.pdf
MALICIOUS — lazonuwiraw.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3b7421622c4d6d9a1221dcac41777bf756b4e930d3e09cb9775000e04455bf40 - SHA-1:
a3bcea0604e6fd728a6846ad62caac48d5db5803 - MD5:
478d4df8b8f2fee704d3f873c91cbac4 - ssdeep:
768:PgGzpDIps5J/dcuDb+8pbipavRI/JY9xH0KxRw0kNnP:4GF0psvZD18k9xUKdkNnP - TLSH:
T1C3329CF350ABED4C39CB9B8399A711556089C68C613397A0848C762DD6B83FDBF11960 - Submitted as: lazonuwiraw.pdf
- File type: pdf · Size: 45704 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/3409757.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=fabriquer%20un%20fumoir%20a%20saumon, https://uploads.strikinglycdn.com/files/b431fb0e-5aff-4625-a119-a35d44aedcf6/wanusenod.pdf, https://uploads.strikinglycdn.com/files/cc201f78-fb7f-45aa-8dc5-fe6992d7ecb0/mobesilanusenakomebevem.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=fabriquer%20un%20fumoir%20a%20saumon
- https://uploads.strikinglycdn.com/files/b431fb0e-5aff-4625-a119-a35d44aedcf6/wanusenod.pdf
- https://uploads.strikinglycdn.com/files/cc201f78-fb7f-45aa-8dc5-fe6992d7ecb0/mobesilanusenakomebevem.pdf
- https://uploads.strikinglycdn.com/files/387d2c37-da5c-4023-b4b0-d0fed5686b53/2637544414.pdf
- https://uploads.strikinglycdn.com/files/197d72aa-5243-474f-8124-41ae811eeec2/20571131312.pdf
- https://uploads.strikinglycdn.com/files/708514ef-d1df-4863-b7db-1861ac9ebb16/20210800286.pdf
- https://mojenosude.weebly.com/uploads/1/3/1/3/131382274/miwegewukodemix.pdf
- https://nogafuku.weebly.com/uploads/1/3/2/8/132815296/7460934.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/3409757.pdf
- https://fadusoga.weebly.com/uploads/1/3/0/7/130739873/nikoseket.pdf
- https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/nafinowe.pdf
- https://uploads.strikinglycdn.com/files/a06494cd-449e-4392-b257-6ca51a22f8d4/wurafav.pdf
- https://uploads.strikinglycdn.com/files/33c59c98-b8cf-4a30-a801-49f93e663a37/gitalojitamapejegilad.pdf
- https://site-1037894.mozfiles.com/files/1037894/15738605135.pdf
- https://site-1040347.mozfiles.com/files/1040347/26863528482.pdf
- https://cdn.shopify.com/s/files/1/0430/3080/6679/files/wet_well_manual.pdf
- https://cdn.shopify.com/s/files/1/0430/3224/8469/files/models_by_mark_manson_free.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/aa94aa7f99c.pdf
- https://nanorobudilason.weebly.com/uploads/1/3/0/7/130775181/8102170.pdf
- https://rabexowubomisuw.weebly.com/uploads/1/3/1/4/131407155/saragevavelizos-wifuge-zevadorowi-raxosefeva.pdf
- https://gazesomudari.weebly.com/uploads/1/3/1/0/131070071/8793377.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- mojenosude.weebly.com
- nogafuku.weebly.com
- guwomenod.weebly.com
- fadusoga.weebly.com
- dirigesibujov.weebly.com
- site-1037894.mozfiles.com
- site-1040347.mozfiles.com
- cdn.shopify.com
- gimejexoxixaza.weebly.com
- nanorobudilason.weebly.com
- rabexowubomisuw.weebly.com
- gazesomudari.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report