MALICIOUS — lokiwe-rewas-zukokonagowule.pdf
MALICIOUS — lokiwe-rewas-zukokonagowule.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6e0c44be3316dcfbfb6334546fe7e58916245a6e810197a33fbad57b3cf5e80d - SHA-1:
6e710d96593de64bd18f76ac1270a04d51f85474 - MD5:
c0bedfad3e3d26f807c72a48480872ce - ssdeep:
768:IgGzpDfpRVtHWwDCXwF0sBcGVhZsWiNwX3wjioW4o:FGFTp1NFsGVh5iq2ioW4o - TLSH:
T145329DF318DBEC4DBACB5B53A9B710B81089C388716297A0598C7A2CC5BC6AD7F51D10 - Submitted as: lokiwe-rewas-zukokonagowule.pdf
- File type: pdf · Size: 43783 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/1158663.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=gta%20vice%20city%20rar%20file, https://uploads.strikinglycdn.com/files/37052ced-e038-43e8-81cf-61eb109df684/tovebaxijofilenozori.pdf, https://uploads.strikinglycdn.com/files/cff7db05-7a01-433d-844b-6df14dc85487/67738588445.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=gta%20vice%20city%20rar%20file
- https://uploads.strikinglycdn.com/files/37052ced-e038-43e8-81cf-61eb109df684/tovebaxijofilenozori.pdf
- https://uploads.strikinglycdn.com/files/cff7db05-7a01-433d-844b-6df14dc85487/67738588445.pdf
- https://uploads.strikinglycdn.com/files/68041271-b500-4c8e-8c96-18ebb4065185/81078412791.pdf
- https://site-1038604.mozfiles.com/files/1038604/dotunedapolalided.pdf
- https://fanavepuru.weebly.com/uploads/1/3/1/8/131871984/sevizo.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/wogiselaruto-nokage.pdf
- https://tipefejiri.weebly.com/uploads/1/3/0/9/130969755/65bf7dd0f0f3.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/1158663.pdf
- https://site-1039899.mozfiles.com/files/1039899/47264231802.pdf
- https://site-1043699.mozfiles.com/files/1043699/57534071858.pdf
- https://site-1043371.mozfiles.com/files/1043371/79403952624.pdf
- https://cdn-cms.f-static.net/uploads/4368758/normal_5f87b80b54231.pdf
- https://cdn-cms.f-static.net/uploads/4366336/normal_5f88160a6f2bf.pdf
- https://cdn-cms.f-static.net/uploads/4367951/normal_5f87b1954b671.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f870413a53c0.pdf
- https://uploads.strikinglycdn.com/files/4874f213-3426-49ef-a498-ae8bb2b312b0/dabulukudumizedadewopebe.pdf
- https://uploads.strikinglycdn.com/files/7b1575c5-2826-49b4-a656-93dd63b4ac3b/63009218185.pdf
- https://uploads.strikinglycdn.com/files/c856dd66-8652-4e7a-b8c1-3d7e55c2b156/potagutopefumaxulirat.pdf
- https://uploads.strikinglycdn.com/files/b32416fe-a32f-4b89-ad86-e43188a81d3e/saxudonigewubaverideju.pdf
- https://uploads.strikinglycdn.com/files/6805e8aa-b095-416f-aaea-79f5e57a0501/69106096282.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1038604.mozfiles.com
- fanavepuru.weebly.com
- xojerajap.weebly.com
- tipefejiri.weebly.com
- dutitujazekap.weebly.com
- site-1039899.mozfiles.com
- site-1043699.mozfiles.com
- site-1043371.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report