MALICIOUS — xevenezegoja.pdf
MALICIOUS — xevenezegoja.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7f1c1a63aa686d3de3611e3747e00e80e76252fd71ac2b58d2f266412c3b7bc7 - SHA-1:
679399f785ad5836870d8971284785ef0b7d0475 - MD5:
dda2893fbddb2a7b2ec263e61b85ff3e - ssdeep:
1536:yGFqpjl43VDikwUKFpUdRLYZMR94fwJwBOBu9kBaH6MLm:rFqpJ43V+5FpUdRM+qf7OMH6F - TLSH:
T13635CFF750E7EC4C7A8B4B07ACEA1226B49982CC9137C754588C396DC8BC67D6F10861 - Submitted as: xevenezegoja.pdf
- File type: pdf · Size: 62910 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/0cbd7f35736ab.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=clarion%20cz702%20review, https://gikoberi.weebly.com/uploads/1/3/0/9/130969260/f035a.pdf, https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/0cbd7f35736ab.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=clarion%20cz702%20review
- https://gikoberi.weebly.com/uploads/1/3/0/9/130969260/f035a.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/0cbd7f35736ab.pdf
- https://jurizimobijagi.weebly.com/uploads/1/3/0/8/130874317/nuvotuzopib.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/nesubine.pdf
- https://narogigadi.weebly.com/uploads/1/3/0/8/130874066/ad85cfd85.pdf
- https://uploads.strikinglycdn.com/files/3dde15a6-bf28-4921-983d-c44e1e126944/zasenifotepesozutijemujot.pdf
- https://uploads.strikinglycdn.com/files/7d77c190-5d97-4eed-b7c7-691d9aaf8152/dasasenekiwevitut.pdf
- https://uploads.strikinglycdn.com/files/78787a15-9d99-4e9b-945d-8ee2d950a9ad/dekamuduzifawemixapusokon.pdf
- https://site-1043366.mozfiles.com/files/1043366/ravorurigelelaxejovubeniv.pdf
- https://site-1037887.mozfiles.com/files/1037887/joleneborexofaxomebarage.pdf
- https://site-1038372.mozfiles.com/files/1038372/jegodevilabenuxigitumixoj.pdf
- https://site-1042448.mozfiles.com/files/1042448/furela.pdf
- https://site-1038836.mozfiles.com/files/1038836/42922608151.pdf
- https://cdn-cms.f-static.net/uploads/4367633/normal_5f884a1a68bfa.pdf
- https://cdn-cms.f-static.net/uploads/4366982/normal_5f8730bc7816f.pdf
- https://cdn-cms.f-static.net/uploads/4365653/normal_5f87058fb05d1.pdf
- https://cdn-cms.f-static.net/uploads/4367648/normal_5f88611216aee.pdf
- https://cdn-cms.f-static.net/uploads/4365634/normal_5f87644699561.pdf
- https://cdn-cms.f-static.net/uploads/4367004/normal_5f872a27dab0b.pdf
- https://cdn.shopify.com/s/files/1/0483/4669/3781/files/size_guide_uk_4.pdf
- https://cdn.shopify.com/s/files/1/0266/8855/3131/files/78238773661.pdf
- https://cdn.shopify.com/s/files/1/0436/9275/3049/files/gopro_user_instructions.pdf
- https://cdn.shopify.com/s/files/1/0436/9865/1289/files/practice_11-1_simplifying_radicals_worksheet_answers.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- gikoberi.weebly.com
- jakedekokobara.weebly.com
- jurizimobijagi.weebly.com
- gimejexoxixaza.weebly.com
- narogigadi.weebly.com
- uploads.strikinglycdn.com
- site-1043366.mozfiles.com
- site-1037887.mozfiles.com
- site-1038372.mozfiles.com
- site-1042448.mozfiles.com
- site-1038836.mozfiles.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report