MALICIOUS — safomuzojinemitifi.pdf
MALICIOUS — safomuzojinemitifi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
50e87a8027ea07867f4b67d613bb8c889e3438afab90d72047e71b89e0aec93b - SHA-1:
30e276b5f7719e927a3e546688dc8481e7c7267c - MD5:
5a5971b5b341dde906da2c1636215ddb - ssdeep:
1536:HLpk47rkbU0mhKhh2JfrkdYvRqkL0SJO+AVLo36pm8zVYP1j17c3T:rpk47rISKT2ykISs+AVLnp5Va19O - TLSH:
T17E3AE1F3614FDC4C7943EB132AF56098718AC68C6176AF984084BB5CC5B8ABDEE21914 - Submitted as: safomuzojinemitifi.pdf
- File type: pdf · Size: 94350 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://fuparududewon.weebly.com/uploads/1/3/1/8/131856041/degogedego-dojidetudi-zuwixeva-wedupojopofege.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=pirate%20king%20hack%20tool%20free%20download, https://zamosokajuzosa.weebly.com/uploads/1/3/4/6/134651904/zumuzutovux.pdf, https://uploads.strikinglycdn.com/files/5c0e995e-9a63-4650-8227-efc45972c8c1/roku_hd_2500x_manual.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=pirate%20king%20hack%20tool%20free%20download
- https://zamosokajuzosa.weebly.com/uploads/1/3/4/6/134651904/zumuzutovux.pdf
- https://uploads.strikinglycdn.com/files/5c0e995e-9a63-4650-8227-efc45972c8c1/roku_hd_2500x_manual.pdf
- https://doxediseweroz.weebly.com/uploads/1/3/4/6/134634010/87c51.pdf
- https://disadaniti.weebly.com/uploads/1/3/4/4/134463451/suzifedami.pdf
- https://fufivivol.weebly.com/uploads/1/3/0/8/130873849/9862604.pdf
- https://cdn-cms.f-static.net/uploads/4404488/normal_5fbe3211b7924.pdf
- https://fuparududewon.weebly.com/uploads/1/3/1/8/131856041/degogedego-dojidetudi-zuwixeva-wedupojopofege.pdf
- https://uploads.strikinglycdn.com/files/4dd896ee-4cae-4c9c-8411-907eeef2d706/20374928586.pdf
- https://s3.amazonaws.com/dudurat/64054730384.pdf
- https://uploads.strikinglycdn.com/files/dd491c33-b282-49f2-a6c6-0c5b6e606148/fiverafuwo.pdf
- https://uploads.strikinglycdn.com/files/c280050f-9a5d-4465-9a28-280a936d5888/82066031575.pdf
- https://uploads.strikinglycdn.com/files/06424f1d-26f6-4cc3-9a7a-4fdcabc33368/bulomejiguxoxumamuxofos.pdf
- https://zekenegelu.weebly.com/uploads/1/3/4/3/134390475/rejux.pdf
- https://cdn-cms.f-static.net/uploads/4495531/normal_5fd2ce4436b78.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- zamosokajuzosa.weebly.com
- uploads.strikinglycdn.com
- doxediseweroz.weebly.com
- disadaniti.weebly.com
- fufivivol.weebly.com
- cdn-cms.f-static.net
- fuparududewon.weebly.com
- s3.amazonaws.com
- zekenegelu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report