MALICIOUS — sezexo_baboxixofe_dafuxorufow.pdf
MALICIOUS — sezexo_baboxixofe_dafuxorufow.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6277eed04290f4f4851118a6f5723f19b19dd9d7e26b03622a61525332c92867 - SHA-1:
9b3db2885dbd0fb037ee176714494a4225f96600 - MD5:
87b23acc832fa911a9d5489ba70f3f34 - ssdeep:
1536:dGFhppeMXKKiDf0I0o0vOGnfi4/rf7zMy5wVwD78iQ817P91+X/:gFhp4M6xbGvOIfiOrfEyCe1/1r91K - TLSH:
T1FD39D1F36083DD4DBE969F43DAEE14AE6185C78A5036FBC41488363DC5B87AEAD00815 - Submitted as: sezexo_baboxixofe_dafuxorufow.pdf
- File type: pdf · Size: 84808 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://givifajilodox.weebly.com/uploads/1/3/0/8/130874655/96a325964f37b.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=13%20steps%20to%20mentalism%20free%20pdf%20downl, https://cdn.shopify.com/s/files/1/0484/3637/9816/files/elizabeth_arden_flawless_finish.pdf, https://cdn.shopify.com/s/files/1/0494/1214/5308/files/3d_pong_unblocked.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=13%20steps%20to%20mentalism%20free%20pdf%20downl
- https://cdn.shopify.com/s/files/1/0484/3637/9816/files/elizabeth_arden_flawless_finish.pdf
- https://cdn.shopify.com/s/files/1/0494/1214/5308/files/3d_pong_unblocked.pdf
- https://cdn.shopify.com/s/files/1/0483/2103/6452/files/96771414181.pdf
- https://cdn.shopify.com/s/files/1/0500/9198/3013/files/bidufuvanezedivala.pdf
- https://femitinekabel.weebly.com/uploads/1/3/1/4/131437683/c6c4f22299.pdf
- https://ponixojezunuto.weebly.com/uploads/1/3/0/9/130969897/jivasipir_xexisebig.pdf
- https://sovopubi.weebly.com/uploads/1/3/0/7/130775052/94788b6e98.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/bademasotud-muwoxob-keruluzaraji-tiwifozexomepog.pdf
- https://givifajilodox.weebly.com/uploads/1/3/0/8/130874655/96a325964f37b.pdf
- https://givifajilodox.weebly.com/uploads/1/3/0/8/130874655/gowabojin_godol.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/31d6b5ca9.pdf
- https://cdn.shopify.com/s/files/1/0431/0364/9953/files/solving_rational_equations_word_problems_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0433/4413/4294/files/14521905534.pdf
- https://cdn.shopify.com/s/files/1/0496/1442/2169/files/zugewigoranot.pdf
- https://cdn.shopify.com/s/files/1/0493/1734/7494/files/72474117850.pdf
- https://cdn.shopify.com/s/files/1/0434/4456/8216/files/africa_toto_chords.pdf
- https://vodipewelo.weebly.com/uploads/1/3/1/6/131637384/fezezoje_detulekibetid_tewor_vofedadovudixo.pdf
- https://jivexine.weebly.com/uploads/1/3/1/3/131380908/57981fefcf2d6a6.pdf
- https://luwobidope.weebly.com/uploads/1/3/0/8/130814225/5456503.pdf
- https://xedaliwim.weebly.com/uploads/1/3/1/4/131454603/8508ce3c8fc8.pdf
- https://dubuzosokiboxof.weebly.com/uploads/1/3/1/1/131163723/gejufisi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- femitinekabel.weebly.com
- ponixojezunuto.weebly.com
- sovopubi.weebly.com
- xojerajap.weebly.com
- givifajilodox.weebly.com
- vodipewelo.weebly.com
- jivexine.weebly.com
- luwobidope.weebly.com
- xedaliwim.weebly.com
- dubuzosokiboxof.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report