MALICIOUS — mureb.pdf
MALICIOUS — mureb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 1 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5deff7a792594d8ae19c9a41430df3eece0a44e2bb679c14905504f1a36c81df - SHA-1:
f5289299c1cbc78b99056ed9231b499b1d631a00 - MD5:
c309d61a4557500e1ac655d712f39e97 - ssdeep:
768:KgGzpDipmkWAgLMa4Uf/QfUkhu0aFuaV6+:XGFOpnawfxckaV6+ - TLSH:
T11E306CF35197ED8C7BCF1B435EAB119EA086D38D713292904588362DC4B86FD6F10961 - Submitted as: mureb.pdf
- File type: pdf · Size: 36503 bytes
- Verdict: malicious (71/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/serovula.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=osez%20l%20amour%20des%20rondes%20pdf, https://zuwumepegowivos.weebly.com/uploads/1/3/1/0/131069935/3627798.pdf, https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/mezevoxinokimuwamibu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=osez%20l%20amour%20des%20rondes%20pdf
- https://zuwumepegowivos.weebly.com/uploads/1/3/1/0/131069935/3627798.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/mezevoxinokimuwamibu.pdf
- https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/serovula.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/zabajufu-femudana.pdf
- https://site-1037172.mozfiles.com/files/1037172/ritomadomexozuwi.pdf
- https://site-1042198.mozfiles.com/files/1042198/53094587486.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/vaxujow_gebonem.pdf
- https://lulitetuxopibol.weebly.com/uploads/1/3/1/1/131164377/2823319.pdf
- https://xuvakaxatal.weebly.com/uploads/1/3/1/0/131070170/potakote.pdf
- https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/2995731.pdf
- https://xumogimunosu.weebly.com/uploads/1/3/1/6/131607683/jofamep_xevozurenatef.pdf
- https://site-1039443.mozfiles.com/files/1039443/gijemi.pdf
- https://site-1040562.mozfiles.com/files/1040562/wumidijib.pdf
- https://site-1037086.mozfiles.com/files/1037086/21259423688.pdf
- https://site-1040326.mozfiles.com/files/1040326/26523567002.pdf
- https://site-1041854.mozfiles.com/files/1041854/57359871656.pdf
- https://site-1037849.mozfiles.com/files/1037849/tabater.pdf
- https://site-1039800.mozfiles.com/files/1039800/zunakebuwitedina.pdf
- https://site-1040322.mozfiles.com/files/1040322/1052238412.pdf
- https://site-1041615.mozfiles.com/files/1041615/lageg.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- zuwumepegowivos.weebly.com
- xojerajap.weebly.com
- tivakoxidedopa.weebly.com
- jamuseramomuf.weebly.com
- site-1037172.mozfiles.com
- site-1042198.mozfiles.com
- nudojafobedem.weebly.com
- lulitetuxopibol.weebly.com
- xuvakaxatal.weebly.com
- jiwepurojal.weebly.com
- xumogimunosu.weebly.com
- site-1039443.mozfiles.com
- site-1040562.mozfiles.com
- site-1037086.mozfiles.com
- site-1040326.mozfiles.com
- site-1041854.mozfiles.com
- site-1037849.mozfiles.com
- site-1039800.mozfiles.com
- site-1040322.mozfiles.com
- site-1041615.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report