MALICIOUS — gexedopunolap.pdf
MALICIOUS — gexedopunolap.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
683d8e3161497c65695b2d6f81348839c76374fa6281555c367cf95bb5ba0eed - SHA-1:
c75469eb9bbf129fa41158b543c6a8fbb897ec73 - MD5:
2725ba00d1eb0872b458eae06e43ef42 - ssdeep:
768:QgGzpD0pyURa3Pg0AdoF7/Rlwz03hfL06IbGrR+lRR:9GFop8LRc03hfr1rR+lRR - TLSH:
T154327DF32197EE8C6A879B436DA620996445C3C87236C76005DD3B6CC4BC2BD7F109A2 - Submitted as: gexedopunolap.pdf
- File type: pdf · Size: 44318 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/4601264.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=cometas%20asteroides%20y%20meteoritos, https://gekeforoka.weebly.com/uploads/1/3/1/4/131438206/0dbd067e.pdf, https://saxibodusazo.weebly.com/uploads/1/3/0/7/130740440/a552408ff8.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=cometas%20asteroides%20y%20meteoritos
- https://gekeforoka.weebly.com/uploads/1/3/1/4/131438206/0dbd067e.pdf
- https://saxibodusazo.weebly.com/uploads/1/3/0/7/130740440/a552408ff8.pdf
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/278805.pdf
- https://vikumeniwexawud.weebly.com/uploads/1/3/0/9/130969440/8823596.pdf
- https://tidemipevu.weebly.com/uploads/1/3/0/7/130740592/d8997e6decbee90.pdf
- https://cdn.shopify.com/s/files/1/0496/5629/9671/files/xenerepedu.pdf
- https://cdn.shopify.com/s/files/1/0437/7680/2967/files/port_royale_3_guide.pdf
- https://cdn.shopify.com/s/files/1/0484/8926/7362/files/diestel_graph_theory_5th_edition.pdf
- https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/4601264.pdf
- https://netaluzubik.weebly.com/uploads/1/3/0/8/130813777/dobanabe.pdf
- https://uploads.strikinglycdn.com/files/368d6d6a-0717-4581-a082-119d3d203088/62679243469.pdf
- https://uploads.strikinglycdn.com/files/0a2394e8-d23e-4bfb-b5dd-7384374c59d3/wepaxapenisip.pdf
- https://uploads.strikinglycdn.com/files/b65cc8d9-7b62-47f2-85cd-b919c6c7bcb3/72429896110.pdf
- https://uploads.strikinglycdn.com/files/6bbd3a07-2ec1-4576-8316-c8be6b17425f/wazaxurebux.pdf
- https://bakuwosir.weebly.com/uploads/1/3/0/8/130874569/c8851.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/kinufijozulof.pdf
- https://givifajilodox.weebly.com/uploads/1/3/0/8/130874655/rivibozedugamag.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/divili_dapixi.pdf
- https://vupimolafi.weebly.com/uploads/1/3/1/3/131398504/13f7fc31126e959.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- gekeforoka.weebly.com
- saxibodusazo.weebly.com
- pigogokeda.weebly.com
- vikumeniwexawud.weebly.com
- tidemipevu.weebly.com
- cdn.shopify.com
- tivakoxidedopa.weebly.com
- netaluzubik.weebly.com
- uploads.strikinglycdn.com
- bakuwosir.weebly.com
- vuxozajuje.weebly.com
- givifajilodox.weebly.com
- jakedekokobara.weebly.com
- vupimolafi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report