MALICIOUS — lewetomilijejebidowu.pdf
MALICIOUS — lewetomilijejebidowu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
546e87a7cc901ba5683f64642b2e3174cbf6251871cb0e48dc6ab7b5fbf6a291 - SHA-1:
75761bd7eb4f0dc78d3db0c07352dd31365002c3 - MD5:
eda06a5375c4c8ea8212304452a50b52 - ssdeep:
768:egGzpD2ejAZ8/SFg6j38AucdnAJ2vbzgweJYzssRYThtKXYACwLYCVWQGHg3W:bGFyeR6gAS4eGz/RFXYfcYgHGoW - TLSH:
T17A339EF35067EC8C7ACFAF43A8A7109A7097D28C653297E05988776CC47CABD6E10911 - Submitted as: lewetomilijejebidowu.pdf
- File type: pdf · Size: 52042 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/77959.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=scat%20engine%20kits, https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/77959.pdf, https://zimiduninu.weebly.com/uploads/1/3/1/6/131637103/woxuzobusijuxur-bazomebuzib-tifivegowoxop-vabeleg.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=scat%20engine%20kits
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/77959.pdf
- https://zimiduninu.weebly.com/uploads/1/3/1/6/131637103/woxuzobusijuxur-bazomebuzib-tifivegowoxop-vabeleg.pdf
- https://pidofuvu.weebly.com/uploads/1/3/0/7/130739764/6380387.pdf
- https://cdn.shopify.com/s/files/1/0484/5148/5850/files/32189209925.pdf
- https://cdn.shopify.com/s/files/1/0497/7524/7521/files/fourth_great_awakening_apush.pdf
- https://cdn.shopify.com/s/files/1/0483/9561/6407/files/nate_and_serena_gif.pdf
- https://cdn-cms.f-static.net/uploads/4369323/normal_5f87aecfca184.pdf
- https://cdn-cms.f-static.net/uploads/4366057/normal_5f87248e1c91d.pdf
- https://nanorobudilason.weebly.com/uploads/1/3/0/7/130775181/cdda8a3bd8f4.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/1392291.pdf
- https://tikedamo.weebly.com/uploads/1/3/1/4/131453682/zelosalazaribataf.pdf
- https://zulatikuwa.weebly.com/uploads/1/3/0/7/130776211/9673907.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/297c0.pdf
- https://site-1038707.mozfiles.com/files/1038707/wupavosusovobavisurezux.pdf
- https://site-1042733.mozfiles.com/files/1042733/piwavelijufanimelam.pdf
- https://site-1038339.mozfiles.com/files/1038339/38427631137.pdf
- https://site-1039666.mozfiles.com/files/1039666/mean_ungrouped_data.pdf
- https://cdn-cms.f-static.net/uploads/4366348/normal_5f87467edd2ae.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f870741e5377.pdf
- https://cdn-cms.f-static.net/uploads/4366337/normal_5f8716a9998f1.pdf
- https://cdn-cms.f-static.net/uploads/4369173/normal_5f87b69738942.pdf
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f87f073db2e8.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- megadezatesaram.weebly.com
- zimiduninu.weebly.com
- pidofuvu.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- nanorobudilason.weebly.com
- xojerajap.weebly.com
- tikedamo.weebly.com
- zulatikuwa.weebly.com
- guwomenod.weebly.com
- site-1038707.mozfiles.com
- site-1042733.mozfiles.com
- site-1038339.mozfiles.com
- site-1039666.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report