MALICIOUS — lokoluditi.pdf
MALICIOUS — lokoluditi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5639a7086fc5693fe6c7d109f22950804bbbd6e42dec36de63f41358991ab2eb - SHA-1:
432c240dc7e236459f17d33e300e84bf8632da12 - MD5:
889006e0e9b258842240e88ef45f5351 - ssdeep:
1536:hGF9pvt0k9EoojfLnPfczBzZ1RfYherBdy:EF9pvH2XvP0FzNfYkrG - TLSH:
T1D634CFF31097DC4D7B896B03BCA6105E9689D38C9036D6A2588C773CE57C6ADAF11860 - Submitted as: lokoluditi.pdf
- File type: pdf · Size: 54591 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/288035.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=communication%20commerciale%20pdf, https://cdn-cms.f-static.net/uploads/4370052/normal_5f88074ae70d1.pdf, https://cdn-cms.f-static.net/uploads/4367308/normal_5f875c59f31d4.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=communication%20commerciale%20pdf
- https://cdn-cms.f-static.net/uploads/4370052/normal_5f88074ae70d1.pdf
- https://cdn-cms.f-static.net/uploads/4367308/normal_5f875c59f31d4.pdf
- https://cdn-cms.f-static.net/uploads/4374371/normal_5f8b3a81805fb.pdf
- https://cdn-cms.f-static.net/uploads/4366628/normal_5f8bcd705000c.pdf
- https://cdn-cms.f-static.net/uploads/4379229/normal_5f8bcd2627324.pdf
- https://nurekagenarufab.weebly.com/uploads/1/3/1/6/131636906/7092920.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/288035.pdf
- https://vewutaniwem.weebly.com/uploads/1/3/0/8/130873717/zitakeg.pdf
- https://cdn.shopify.com/s/files/1/0498/4599/3634/files/20901112262.pdf
- https://cdn.shopify.com/s/files/1/0430/7435/5351/files/lafezaril.pdf
- https://cdn.shopify.com/s/files/1/0432/6627/7534/files/76671001833.pdf
- https://cdn.shopify.com/s/files/1/0484/7439/0678/files/vintage_polaris_snowmobile_manuals.pdf
- https://cdn.shopify.com/s/files/1/0437/2434/1400/files/grand_theft_auto_san_andreas_apk_free_download_ios.pdf
- https://cdn.shopify.com/s/files/1/0434/5587/3190/files/57886883306.pdf
- https://cdn.shopify.com/s/files/1/0486/7145/7430/files/59654190872.pdf
- https://cdn.shopify.com/s/files/1/0495/4809/9736/files/1-99_hunter_guide_osrs_2019.pdf
- https://cdn.shopify.com/s/files/1/0498/8675/7018/files/wikazuvikuwodazozin.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/honda_ecm_2800_manual.pdf
- https://cdn.shopify.com/s/files/1/0434/0324/7781/files/zewobatumuposinetirila.pdf
- https://cdn.shopify.com/s/files/1/0484/8327/0817/files/figagusefusanevoluz.pdf
- https://cdn.shopify.com/s/files/1/0268/7533/0755/files/principles_of_warehouse_design.pdf
- https://cdn.shopify.com/s/files/1/0433/4590/3774/files/68904615784.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- nurekagenarufab.weebly.com
- jufaxexave.weebly.com
- vewutaniwem.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report