MALICIOUS — xutiludaruw_zakis.pdf
MALICIOUS — xutiludaruw_zakis.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
40be069f33b59e74bc1710b5fce357797f64c7f27c394dcdd94837b4302f51f8 - SHA-1:
47bdd8f01e100ad4493197a68a3ce80dd05fe7ea - MD5:
c8c9d57dd283be2b620744341473e0b0 - ssdeep:
3072:LFrpPUbjvYPpekFI8FyHbL4JOKrDYqCO2wSg7NL56:5dCkxekFnwb4OjBzh - TLSH:
T1E13EF1F35057DD1CE6CBA76BA8B90129758D9B8C5021F3981AC8732CD6B86BC5D20D31 - Submitted as: xutiludaruw_zakis.pdf
- File type: pdf · Size: 143152 bytes
- Verdict: malicious (87/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 87/100 is the fusion of 5 weighted signals:
- Embedded link rated malicious by URL analysis: https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/09427c23789b.pdf - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://gettraff.ru/wb?keyword=ps2%20games%20collection%20download, https://uploads.strikinglycdn.com/files/56464d60-7c3f-47fa-9bae-0712af96c0c9/gogumufegiduwonifubezi.pdf, https://uploads.strikinglycdn.com/files/f1c1df40-4261-41fa-8108-ceb666e439b9/31740616518.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=ps2%20games%20collection%20download
- https://uploads.strikinglycdn.com/files/56464d60-7c3f-47fa-9bae-0712af96c0c9/gogumufegiduwonifubezi.pdf
- https://uploads.strikinglycdn.com/files/f1c1df40-4261-41fa-8108-ceb666e439b9/31740616518.pdf
- https://uploads.strikinglycdn.com/files/d78b6f75-3ed9-49d6-8656-def68e39ec40/45270234236.pdf
- https://uploads.strikinglycdn.com/files/d594955c-581a-4f2e-87f8-1d277c3479af/gaxorusupug.pdf
- https://uploads.strikinglycdn.com/files/ed0a14d4-c1d0-4832-adc6-a06733481e16/19003343486.pdf
- https://uploads.strikinglycdn.com/files/866713b4-7442-4985-aadc-ea3db0a2d568/1367765432.pdf
- https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/09427c23789b.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/mikukinib.pdf
- https://cdn.shopify.com/s/files/1/0498/9639/0814/files/app_sms_contact_backup_apk.pdf
- https://cdn.shopify.com/s/files/1/0503/6507/1520/files/estructura_de_un_texto_expositivo.pdf
- https://cdn.shopify.com/s/files/1/0437/7355/8935/files/blossom_blast_saga_apk4fun.pdf
- https://cdn.shopify.com/s/files/1/0493/1829/7759/files/lutosokumisulowojegejer.pdf
- https://cdn.shopify.com/s/files/1/0432/6172/2786/files/terminal_emulator_apk.pdf
- https://uploads.strikinglycdn.com/files/bb946fc8-f4ff-40b9-a0c1-f41e69637565/24102159637.pdf
- https://uploads.strikinglycdn.com/files/8f0c1793-af74-492b-b959-882be8964601/20609748662.pdf
- https://uploads.strikinglycdn.com/files/f0e3c83f-113d-4717-847c-f9cc2ef6baa5/37611613064.pdf
- https://uploads.strikinglycdn.com/files/2eb2da3f-aa2f-4f40-a4c9-4a8f4df1be6d/27132659052.pdf
- https://uploads.strikinglycdn.com/files/6ad5b7a5-9c72-41c8-9dd7-3466998f9dc3/88772965583.pdf
- https://cdn-cms.f-static.net/uploads/4366005/normal_5f8911d8f143b.pdf
- https://cdn-cms.f-static.net/uploads/4373301/normal_5f899e1d23402.pdf
- https://cdn-cms.f-static.net/uploads/4372371/normal_5f8940919328c.pdf
- https://cdn-cms.f-static.net/uploads/4366000/normal_5f886c33a864b.pdf
- https://cdn-cms.f-static.net/uploads/4367275/normal_5f87434857aea.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- sb.su
- uploads.strikinglycdn.com
- mupibidegupek.weebly.com
- keniwuki.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report