MALICIOUS — pafufovuzisunemu.pdf
MALICIOUS — pafufovuzisunemu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
423f0c1ee8c561056e1040bc89672d779ee5297c4a2562ea1c48cc365a1bfc08 - SHA-1:
1233837030fcac60710d11089942c8bdb2bbdf0f - MD5:
b270d6d9606f26a4a4b03a4a5e22824b - ssdeep:
768:PagGzpDDe1CIWn52s3gnL1ogwrQulWxrqQhmY9a+6cVh/d+eXlPWYURE:vGFHe1YKoNrurFhG+hVhl+AlP3URE - TLSH:
T193339FF3509BDD8C7A86AB03ADFB0195908AC38972269B90588C773DD17CAFD6F50910 - Submitted as: pafufovuzisunemu.pdf
- File type: pdf · Size: 47921 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/d73b6a65c079055.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=voice+recorder+app+android+best, https://uploads.strikinglycdn.com/files/e628ac98-8c72-4748-96ae-fc22c87cd415/77779331740.pdf, https://uploads.strikinglycdn.com/files/99dad67d-5561-4fb9-866e-3f34919e0134/56193211535.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=voice+recorder+app+android+best
- https://uploads.strikinglycdn.com/files/e628ac98-8c72-4748-96ae-fc22c87cd415/77779331740.pdf
- https://uploads.strikinglycdn.com/files/99dad67d-5561-4fb9-866e-3f34919e0134/56193211535.pdf
- https://uploads.strikinglycdn.com/files/3d45f450-f7ad-42d9-b0d7-2471644024d2/86518732385.pdf
- https://site-1043576.mozfiles.com/files/1043576/36765770790.pdf
- https://site-1038897.mozfiles.com/files/1038897/mawujusase.pdf
- https://site-1048557.mozfiles.com/files/1048557/sebilosereludomu.pdf
- https://site-1038508.mozfiles.com/files/1038508/50037720455.pdf
- https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/gonumuxilalap_kupepe.pdf
- https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/d73b6a65c079055.pdf
- https://cdn-cms.f-static.net/uploads/4369152/normal_5f87bf0b9e45b.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f87bca0e8507.pdf
- https://cdn-cms.f-static.net/uploads/4369773/normal_5f88070dbd267.pdf
- https://uploads.strikinglycdn.com/files/1fd46b86-23d8-4209-bb0d-59f1dd79eb6a/93575815474.pdf
- https://uploads.strikinglycdn.com/files/9936bacf-5760-4fc8-8360-9bcea60b2fbe/19048581650.pdf
- https://uploads.strikinglycdn.com/files/8a2fdc7d-a155-4e1a-a69b-b13e737aff87/91903795113.pdf
- https://uploads.strikinglycdn.com/files/68d0fed3-9252-4fe5-aada-46441c98983f/mudejarudim.pdf
- https://uploads.strikinglycdn.com/files/10f6707e-7e93-45a6-91a0-6bf602985bed/lozewililede.pdf
- https://site-1036716.mozfiles.com/files/1036716/wusefofereriwet.pdf
- https://site-1040251.mozfiles.com/files/1040251/fopokapevupet.pdf
- https://site-1043564.mozfiles.com/files/1043564/80622870964.pdf
- https://site-1036729.mozfiles.com/files/1036729/61954918894.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1043576.mozfiles.com
- site-1038897.mozfiles.com
- site-1048557.mozfiles.com
- site-1038508.mozfiles.com
- mupibidegupek.weebly.com
- povutepumik.weebly.com
- cdn-cms.f-static.net
- site-1036716.mozfiles.com
- site-1040251.mozfiles.com
- site-1043564.mozfiles.com
- site-1036729.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report