MALICIOUS — tufizo.pdf
MALICIOUS — tufizo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (77/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7fde445d2a85d8846558e8eb30f1101fb83362d49100f2682fa9032abf55fda9 - SHA-1:
41873d6dcfc0fedcd6f833d143bad1ca1fa9bec6 - MD5:
5cc97ac5a55b593073a6a1a2ce0941ac - ssdeep:
768:WcgGzpD/y76gsPYbPoywyZKPPpKDzGyPF6Yp1PHvLpKVVeek2kohxVnHWG6+pAhL:WGFTMSOkgkpKrPF71PvgVVeB2kUHnHWN - TLSH:
T116339FF311ABEC8C768A9F039AA71558904ADB887031D7E04589777CC47C6FD6E10E52 - Submitted as: tufizo.pdf
- File type: pdf · Size: 48110 bytes
- Verdict: malicious (77/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 77/100 is the fusion of 5 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/4d3df997-0ada-4a4b-a423-217656743ce4/fiwatemifav.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=mp3xd+descargar+musica+gratis+para+android+app, https://uploads.strikinglycdn.com/files/4d3df997-0ada-4a4b-a423-217656743ce4/fiwatemifav.pdf, https://uploads.strikinglycdn.com/files/2aba216f-baed-481d-a28e-c55ff028ca4e/73739147187.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=mp3xd+descargar+musica+gratis+para+android+app
- https://uploads.strikinglycdn.com/files/4d3df997-0ada-4a4b-a423-217656743ce4/fiwatemifav.pdf
- https://uploads.strikinglycdn.com/files/2aba216f-baed-481d-a28e-c55ff028ca4e/73739147187.pdf
- https://uploads.strikinglycdn.com/files/7f0f8560-01a6-49f6-943c-d275b06ceec2/bipigikukafez.pdf
- https://uploads.strikinglycdn.com/files/9a9c3fec-ddd3-4136-8433-2a44f8ed2fe0/kexulomogolumawibepejidi.pdf
- http://files.bshcare.com/uploads/1/3/0/8/130813710/752154.pdf
- http://bemew.andrewcoxacoustic.com/uploads/1/3/1/3/131398036/rawosakujos.pdf
- http://gazulojan.stylebybarbara.com/uploads/1/3/1/6/131636947/ed7245e9b5640c7.pdf
- http://wowejer.college-elf.com/uploads/1/3/0/8/130874376/8348339.pdf
- https://uploads.strikinglycdn.com/files/0d764511-f26c-485a-a74c-af4df065c53c/98221455754.pdf
- https://uploads.strikinglycdn.com/files/addb2edf-d01c-4bf8-ad67-55dc6a544e7b/jalabofijosojikej.pdf
- http://files.eleganzawaackingfestival.com/uploads/1/3/1/8/131856903/dfcd8.pdf
- http://zosiz.sandiegosuzukiinstitute.com/uploads/1/3/1/4/131437254/5ffc28b08c256d.pdf
- http://molopixo.glam2bella.com/uploads/1/3/2/6/132680896/b4fa16f5e0c9.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- files.bshcare.com
- bemew.andrewcoxacoustic.com
- gazulojan.stylebybarbara.com
- wowejer.college-elf.com
- files.eleganzawaackingfestival.com
- zosiz.sandiegosuzukiinstitute.com
- molopixo.glam2bella.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- W:\,
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report