MALICIOUS — xewezemagiko.pdf
MALICIOUS — xewezemagiko.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7d2937b4d333b0db6a0fa2491bd71fd6269fbaace93953fa120e8322c8ffbf94 - SHA-1:
87fecf323541eaba66a9a9a203fcfc1ba0e152ad - MD5:
f5c0775c81b62f0c8294ebceaf0bba00 - ssdeep:
3072:TFRwgwpOgzxPO7PyGCzVoMtXLBclSDmjL2b+2Js/:Br5pnCzVoMVLBuDjqJg - TLSH:
T1B93CF1B3A057DE4C36CBBF0399A52069A04BDA493232C6A418CD6A7CC9BC7FC5E50D50 - Submitted as: xewezemagiko.pdf
- File type: pdf · Size: 121176 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/c075d12a-a14d-472f-a905-df1e64a947e2/jeluralobevigegogalaj.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=quantum+entanglement+theory+pdf, https://cdn.shopify.com/s/files/1/0431/7433/0517/files/concept_of_social_media_advertising.pdf, https://cdn.shopify.com/s/files/1/0437/9885/5837/files/81533671355.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=quantum+entanglement+theory+pdf
- https://cdn.shopify.com/s/files/1/0431/7433/0517/files/concept_of_social_media_advertising.pdf
- https://cdn.shopify.com/s/files/1/0437/9885/5837/files/81533671355.pdf
- https://cdn.shopify.com/s/files/1/0433/0743/4142/files/84556258547.pdf
- https://cdn.shopify.com/s/files/1/0432/4530/6011/files/father_s_day_gift_guide_blog.pdf
- https://uploads.strikinglycdn.com/files/7590e90e-7540-4852-a93e-44123b48dbeb/ralolurepunidamiv.pdf
- https://uploads.strikinglycdn.com/files/c075d12a-a14d-472f-a905-df1e64a947e2/jeluralobevigegogalaj.pdf
- https://uploads.strikinglycdn.com/files/f6950915-9325-42bf-9dae-251b2e35a062/rodevegukotatadinexo.pdf
- https://cdn.shopify.com/s/files/1/0428/2987/3318/files/sudibufawipesa.pdf
- https://cdn.shopify.com/s/files/1/0430/1383/2857/files/ways_of_seeing_book.pdf
- https://cdn.shopify.com/s/files/1/0431/6961/1932/files/59131328165.pdf
- https://cdn.shopify.com/s/files/1/0437/6172/9685/files/callan_method_english_books.pdf
- https://cdn.shopify.com/s/files/1/0432/6440/9755/files/bolanisejagojez.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report