MALICIOUS — xezubekumu-lubudunumofek.pdf
MALICIOUS — xezubekumu-lubudunumofek.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8855255db4ddef2faaf17468f7ff98d264c92c2cd7c49bedd4088cdd919d34de - SHA-1:
44aac0ac76d50d84118e41622d54317919b2c19b - MD5:
479b02c403367e2f3da1fecb9ccda4de - ssdeep:
768:4gGzpDFpNs3FDO30xaB4bgBVsIRpTzsde2YU80e:VGFppk7bgTFRpnke480e - TLSH:
T1E3306CF31067ED8CBA8BAB476DEA159A6589D38D6033D760448C772CC5BC2BD6F10860 - Submitted as: xezubekumu-lubudunumofek.pdf
- File type: pdf · Size: 36745 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/36ce75ac.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=namaz%20sureleri%20sesli%20indir, https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/36ce75ac.pdf, https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/5100849.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=namaz%20sureleri%20sesli%20indir
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/36ce75ac.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/5100849.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/zanadutut_wexudafenatogun_jetomefoja.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/1158663.pdf
- https://cdn.shopify.com/s/files/1/0480/8422/2116/files/mov_vs_mp4.pdf
- https://cdn.shopify.com/s/files/1/0501/1223/3667/files/ibnu_khaldun_muqaddimah.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f88ba3c55ae7.pdf
- https://cdn-cms.f-static.net/uploads/4367656/normal_5f875c9a62ac7.pdf
- https://site-1037057.mozfiles.com/files/1037057/difutuxobegega.pdf
- https://site-1039328.mozfiles.com/files/1039328/57235889062.pdf
- https://site-1041084.mozfiles.com/files/1041084/powamijepazevega.pdf
- https://site-1036852.mozfiles.com/files/1036852/roxukumemupe.pdf
- https://uploads.strikinglycdn.com/files/e12aac08-e9d0-4f87-afcc-2058e2e57f5e/detevowifeje.pdf
- https://uploads.strikinglycdn.com/files/c40bf07d-1656-447e-9722-edd82f63709c/wixuvakezuzexuweberom.pdf
- https://uploads.strikinglycdn.com/files/21b214e0-425c-450b-aaed-fb6921202955/18218176496.pdf
- https://uploads.strikinglycdn.com/files/2c8625c3-64b0-4c1f-a8c9-36a1ea5be926/83788348426.pdf
- https://cdn.shopify.com/s/files/1/0500/8202/1548/files/hola_launcher_pro_apk.pdf
- https://cdn.shopify.com/s/files/1/0266/7613/4082/files/benchmade_mel_pardue_auto.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- dutitujazekap.weebly.com
- boguvetasitob.weebly.com
- jakedekokobara.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1037057.mozfiles.com
- site-1039328.mozfiles.com
- site-1041084.mozfiles.com
- site-1036852.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report