MALICIOUS — xebozaxugudezat.pdf
MALICIOUS — xebozaxugudezat.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
62e138577038d102560f600c6f57d8c366bbe6867e384c2b93e15733e050cfc1 - SHA-1:
75307cdb652539bbca7c021e9fa036de500d54fc - MD5:
a702a86edae2de6e2a56b236594a74dc - ssdeep:
3072:YFsp6lpovSuVorlcEYIfHKhSzRtz9DRUyVb+nGU93Jcp1jxp:Qu6fDuVelXYeKhSFzDRUOb+GeSpF - TLSH:
T1B73DF1F351A7DE4D3E8B9B83ACE7019D6196D6887431A27054D87A6CC4783FDAF00A21 - Submitted as: xebozaxugudezat.pdf
- File type: pdf · Size: 135561 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/3405140.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=fisica%20moderna%20tipler, https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/3405140.pdf, https://fadusoga.weebly.com/uploads/1/3/0/7/130739873/tozizibuxiwo-zitemo-wewijunofe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=fisica%20moderna%20tipler
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/3405140.pdf
- https://fadusoga.weebly.com/uploads/1/3/0/7/130739873/tozizibuxiwo-zitemo-wewijunofe.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/tidivobinimigip-banez-batipafon.pdf
- https://site-1039000.mozfiles.com/files/1039000/zuzew.pdf
- https://uploads.strikinglycdn.com/files/0c44815b-aa4f-4bfd-b53f-b1d87c525e52/21875470940.pdf
- https://uploads.strikinglycdn.com/files/18ba017d-1b12-4d9a-9c56-17b1aac748cd/3905514275.pdf
- https://uploads.strikinglycdn.com/files/4e264207-8667-4177-a475-4d34b5a2dc2e/14778419556.pdf
- https://uploads.strikinglycdn.com/files/c1606f6d-c25e-4a53-b448-42476ae114b7/vosufobokafigevewotitujo.pdf
- https://uploads.strikinglycdn.com/files/41a6bee7-d476-4755-a86e-01dfb1cf88f4/tigenomeranogisaj.pdf
- https://site-1042731.mozfiles.com/files/1042731/43363453464.pdf
- https://site-1044109.mozfiles.com/files/1044109/45907389377.pdf
- https://site-1042737.mozfiles.com/files/1042737/zevagewodubokusogu.pdf
- https://uploads.strikinglycdn.com/files/b531714c-91e2-4dcd-a929-702afb9022e7/19159904747.pdf
- https://uploads.strikinglycdn.com/files/3cc62141-0bd9-42b6-be50-cb7a014ed1ce/6300799202.pdf
- https://uploads.strikinglycdn.com/files/fd31aa0e-853c-4947-8d37-70edb937b2f0/71119591101.pdf
- https://uploads.strikinglycdn.com/files/0f940cfb-3d5e-4bfc-aadb-0e8491740987/61458023018.pdf
- https://site-1042736.mozfiles.com/files/1042736/71983550695.pdf
- https://site-1038970.mozfiles.com/files/1038970/42497953896.pdf
- https://site-1038944.mozfiles.com/files/1038944/zejazemewopu.pdf
- https://site-1042282.mozfiles.com/files/1042282/77233773672.pdf
- https://site-1043939.mozfiles.com/files/1043939/dukifom.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- rabifupokuwu.weebly.com
- fadusoga.weebly.com
- zoxuzuxebexot.weebly.com
- site-1039000.mozfiles.com
- uploads.strikinglycdn.com
- site-1042731.mozfiles.com
- site-1044109.mozfiles.com
- site-1042737.mozfiles.com
- site-1042736.mozfiles.com
- site-1038970.mozfiles.com
- site-1038944.mozfiles.com
- site-1042282.mozfiles.com
- site-1043939.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report