MALICIOUS — pevisofefovosuvo.pdf
MALICIOUS — pevisofefovosuvo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8656799d8844e4b8e65f92eb30c37b3d520ba4afd64145b90c45d23a9c7e653e - SHA-1:
e2ec786e66e32f8c766da07b2eaac6e9f7c7628c - MD5:
75c149574e2474d0f1a6ac3a3d307ecf - ssdeep:
768:FgGzpDDkpW7o+xeQe7JeTYO13VCcO5MPCR6mU4zbrzVwiot:WGF3kpyTYO1FCcO5x4mnzbrhWt - TLSH:
T18A31AEF794A7DC8C7A87AB13ADF7001A114AC38C62329764459C7B6CC4BC5BE7D20551 - Submitted as: pevisofefovosuvo.pdf
- File type: pdf · Size: 42726 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/gevoderovepiru.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=business%20proposal%20template%20australia, https://wesoxiworikezux.weebly.com/uploads/1/3/1/3/131380467/2dcf70f3.pdf, https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/gevoderovepiru.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=business%20proposal%20template%20australia
- https://wesoxiworikezux.weebly.com/uploads/1/3/1/3/131380467/2dcf70f3.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/gevoderovepiru.pdf
- https://gusumadanu.weebly.com/uploads/1/3/2/6/132695601/7306898.pdf
- https://zimiduninu.weebly.com/uploads/1/3/1/6/131637103/cafd84665a2f48.pdf
- https://cdn.shopify.com/s/files/1/0481/7898/7165/files/zawid.pdf
- https://cdn.shopify.com/s/files/1/0502/4517/3413/files/tibuwa.pdf
- https://cdn.shopify.com/s/files/1/0479/3247/3500/files/darajoxosopikoxo.pdf
- https://cdn.shopify.com/s/files/1/0499/9014/0064/files/37691315805.pdf
- https://cdn.shopify.com/s/files/1/0480/4860/3300/files/tv_repair_guide_in_tamil.pdf
- https://uploads.strikinglycdn.com/files/c22280d3-cd22-4ffb-bc94-37f0b30adf1e/vasarijagezufalewamafise.pdf
- https://uploads.strikinglycdn.com/files/34bc2bcf-c469-4183-a11d-b35b0f409bf7/karunotef.pdf
- https://uploads.strikinglycdn.com/files/2dc2c010-6082-433b-850f-51afadaa2168/kadiwe.pdf
- https://uploads.strikinglycdn.com/files/d6cd1e6a-83b7-4e6b-a593-3d6c433669a7/movokub.pdf
- https://uploads.strikinglycdn.com/files/3e3cd10e-8de4-4073-8679-cb6685bba010/vugavefepukezaririfomadi.pdf
- https://uploads.strikinglycdn.com/files/757f7449-4433-4696-a05a-86cd621c96d4/20860798446.pdf
- https://uploads.strikinglycdn.com/files/08c5d985-6ebc-4df9-b427-ba1d012a8bbb/14034973271.pdf
- https://uploads.strikinglycdn.com/files/fd223d8d-5872-4a4d-a5f8-54898f62368b/lamefuguli.pdf
- https://cdn.shopify.com/s/files/1/0428/8197/4435/files/dofiniluwewodekalojazir.pdf
- https://cdn.shopify.com/s/files/1/0434/4519/0821/files/gen_2_camaro_restomod.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- wesoxiworikezux.weebly.com
- jawasolasazilem.weebly.com
- gusumadanu.weebly.com
- zimiduninu.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report