MALICIOUS — zuratexizi.pdf
MALICIOUS — zuratexizi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4f07df80e34003e4abaf1c125a651ad479fd2731131b61ede1dc8b4bfd286ad3 - SHA-1:
84c419ae7be69a7a217aab820a386ba3b0784c72 - MD5:
1ff9626b3af6a06a47ae4ae2380c66d4 - ssdeep:
768:7gGzpDUpHRvnLknGQ86ZTRR1amtjn2L/6Esjc2r9LNt3cyJPP3fi3n7TLvVB54:EGFwpHRoDln22nZt3Nvi3Tx4 - TLSH:
T1C4329DF35097EC8C7ECB9B43AEEB10A9608DD789A1269750058C3B6DD0B85ED7F10950 - Submitted as: zuratexizi.pdf
- File type: pdf · Size: 45427 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/godekux.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=astral%20projection%20step%20by%20step%20guide, https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/godekux.pdf, https://pevugubak.weebly.com/uploads/1/3/2/7/132740457/7271212.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=astral%20projection%20step%20by%20step%20guide
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/godekux.pdf
- https://pevugubak.weebly.com/uploads/1/3/2/7/132740457/7271212.pdf
- https://xawuwotogot.weebly.com/uploads/1/3/2/6/132695388/6d4b79f39c6578e.pdf
- https://nikoxutaju.weebly.com/uploads/1/3/1/3/131378952/3379189.pdf
- https://moxitasa.weebly.com/uploads/1/3/1/4/131454719/c21875be9eeb39c.pdf
- https://uploads.strikinglycdn.com/files/74f301e4-ce7d-432a-ae19-109e85b5d957/fuxiluduxeva.pdf
- https://uploads.strikinglycdn.com/files/36c80fab-d966-4362-ba74-fe62df08facc/jazapu.pdf
- https://uploads.strikinglycdn.com/files/f16dadfa-706b-48b0-b0b4-f3966665d2c4/55092151425.pdf
- https://uploads.strikinglycdn.com/files/630519f4-b7ba-464b-a350-bf82d0890884/rutabawudusijugamemirasi.pdf
- https://cdn.shopify.com/s/files/1/0431/8812/5857/files/three_forms_of_verb_chart.pdf
- https://cdn.shopify.com/s/files/1/0475/9306/2556/files/goodgame_empires_hack.pdf
- https://cdn.shopify.com/s/files/1/0497/9818/5109/files/zafexoku.pdf
- https://cdn-cms.f-static.net/uploads/4369146/normal_5f893900a89b4.pdf
- https://cdn-cms.f-static.net/uploads/4366377/normal_5f872280bfa1e.pdf
- https://cdn-cms.f-static.net/uploads/4366402/normal_5f87888f2aadb.pdf
- https://cdn-cms.f-static.net/uploads/4369495/normal_5f8918e4e6f94.pdf
- https://cdn-cms.f-static.net/uploads/4367633/normal_5f874920cb3d3.pdf
- https://uploads.strikinglycdn.com/files/da3debb0-1947-4884-adcc-2c6f98fe19a7/sepilifanasamokakovu.pdf
- https://uploads.strikinglycdn.com/files/8534a21b-0349-4a4e-a5dd-0d9cb5aabf00/47557589480.pdf
- https://uploads.strikinglycdn.com/files/815cf3d2-832c-468d-816c-4f76be7438c8/148262013.pdf
- https://uploads.strikinglycdn.com/files/0fd50516-4164-4d28-8a0e-c85555f432b8/dagujijadozori.pdf
- https://uploads.strikinglycdn.com/files/82204fea-51f6-4d39-b021-282eea26644f/sotegetekimugoton.pdf
- https://cdn.shopify.com/s/files/1/0483/7916/6873/files/57204384659.pdf
- https://cdn.shopify.com/s/files/1/0437/4963/8298/files/connection_timed_out_connect_in_android_studio.pdf
Embedded domains
- cctraff.ru
- jakedekokobara.weebly.com
- pevugubak.weebly.com
- xawuwotogot.weebly.com
- nikoxutaju.weebly.com
- moxitasa.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report