MALICIOUS — menigifudosedegenidofa.pdf
MALICIOUS — menigifudosedegenidofa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
55ee054ddaa3e6254a922b0d1dee8e35eace098a780c9665cce50b48597595a9 - SHA-1:
37234260f27e30a2e66d447e5325885ce93acc59 - MD5:
c053dce6467569b39bd001798e4727b4 - ssdeep:
1536:GGFeeG0A4HfQo32vKEybb1wiCcjtmGl2ym:fFeeG7KYo32vxyv1ic5mGla - TLSH:
T12633AEF310A7DD8C76879B03AEBB0059604ACB497136A6A055CC772CC4BC6FE6F11662 - Submitted as: menigifudosedegenidofa.pdf
- File type: pdf · Size: 51602 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/rebodi.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=3ds+emulator+free+download+for+android+apk, https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/devuxupujikeninaferi.pdf, https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/rebodi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=3ds+emulator+free+download+for+android+apk
- https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/devuxupujikeninaferi.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/rebodi.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/vovofofaverun_sawivurovoj_nifawubazox.pdf
- https://uploads.strikinglycdn.com/files/7b6998fa-b963-4cfc-b472-764484afa708/41417696211.pdf
- https://uploads.strikinglycdn.com/files/9e50b5a4-3285-4871-9951-e841b5c489f7/sesavabepisajokapew.pdf
- https://uploads.strikinglycdn.com/files/9ee10292-76da-4c48-884f-f86cd8122477/45638497529.pdf
- https://uploads.strikinglycdn.com/files/93bb2b06-6e23-407d-b785-2b3bdc0270fa/61207693499.pdf
- https://uploads.strikinglycdn.com/files/2d70bda7-c763-4c30-a294-e966e52f8aa3/39762837147.pdf
- https://cdn.shopify.com/s/files/1/0436/4104/5145/files/51416846438.pdf
- https://cdn.shopify.com/s/files/1/0431/1344/7577/files/tipekaravevofobutifovin.pdf
- https://cdn.shopify.com/s/files/1/0436/1804/2018/files/dymo_11946_letratag_electronic_label_maker_manual.pdf
- https://cdn.shopify.com/s/files/1/0433/5727/4261/files/64328525624.pdf
- https://cdn.shopify.com/s/files/1/0430/0704/9887/files/xatefa.pdf
- https://uploads.strikinglycdn.com/files/886eb813-a778-4877-b6c7-56c76eaadd4f/likagawodororodolowaruxab.pdf
- https://uploads.strikinglycdn.com/files/00e53353-29af-4db8-a5fa-da9cac633a73/kezex.pdf
- https://uploads.strikinglycdn.com/files/402b42a6-c15d-410f-9cd0-2add2747cce3/paralodozoridilazeb.pdf
- https://uploads.strikinglycdn.com/files/878946bc-9221-4e92-b8aa-fcaf7fcf7e1b/mewoworebotumibigavuma.pdf
- https://uploads.strikinglycdn.com/files/aa1d76a7-f53e-4d70-9697-20b12d7d8068/45890498478.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- fodezamu.weebly.com
- jatorogerujew.weebly.com
- genigudepa.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report