MALICIOUS — bakovopu-petanofage-dobegozofudupe.pdf
MALICIOUS — bakovopu-petanofage-dobegozofudupe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
90f8c7e6b3185682f87077d2a50b268d6e8bfb3e8bd08eb56f44ba0bb7454905 - SHA-1:
de64d8fdf8b2bad47bcb634a35f765b853a681a9 - MD5:
dc591d70954caa82e0aa28dd06a2e18d - ssdeep:
768:EgGzpDtpQwJK/YQuJek27K8Fx8DgJcBJAtoMFHYLl4OtdlVtwV1BM1A1Wgg:xGFJpxhGFFyDgJRthHYLFbVtOjg - TLSH:
T15A339EF710D7EC4CBA8A9B079CAB21995489D3487136E7A0888C762DD5BC7BD7F10860 - Submitted as: bakovopu-petanofage-dobegozofudupe.pdf
- File type: pdf · Size: 51843 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://tajurasexir.weebly.com/uploads/1/3/1/6/131606020/1914336.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=milton%20friedman%20negative%20income%20tax, https://tajurasexir.weebly.com/uploads/1/3/1/6/131606020/1914336.pdf, https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/wirexanusir.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=milton%20friedman%20negative%20income%20tax
- https://tajurasexir.weebly.com/uploads/1/3/1/6/131606020/1914336.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/wirexanusir.pdf
- https://liwevapazu.weebly.com/uploads/1/3/1/0/131071299/pojidimuxe.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/5401885.pdf
- https://uploads.strikinglycdn.com/files/cb2267c9-b0e1-4d46-bad0-3f37983b0835/gutabinagagozexad.pdf
- https://uploads.strikinglycdn.com/files/9f15d46e-d26a-46fd-aa72-c76e68ae6b7c/70150356742.pdf
- https://uploads.strikinglycdn.com/files/58fe44a9-0d41-4854-8139-9f6f0c8414e1/negadibovanir.pdf
- https://uploads.strikinglycdn.com/files/667563b7-daa6-437c-9075-43a412440203/60969547515.pdf
- https://uploads.strikinglycdn.com/files/e9087e01-3884-45d1-abd0-f5ced7d50154/wiliduvorokuvexifeg.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/xewuj.pdf
- https://zimiduninu.weebly.com/uploads/1/3/1/6/131637103/7bf0538fede6e3d.pdf
- https://loguxofe.weebly.com/uploads/1/3/0/7/130775118/3331982.pdf
- https://fupexorugukemig.weebly.com/uploads/1/3/0/8/130814763/9844685.pdf
- https://site-1037177.mozfiles.com/files/1037177/83993358107.pdf
- https://site-1043032.mozfiles.com/files/1043032/79312559283.pdf
- https://site-1039828.mozfiles.com/files/1039828/85004102178.pdf
- https://site-1040780.mozfiles.com/files/1040780/rutewob.pdf
- https://site-1043289.mozfiles.com/files/1043289/zanaxagirof.pdf
- https://site-1040575.mozfiles.com/files/1040575/bowoludoratenera.pdf
- https://site-1039492.mozfiles.com/files/1039492/76700745685.pdf
- https://site-1043766.mozfiles.com/files/1043766/fixivoraxuzukaxasojino.pdf
- https://site-1043086.mozfiles.com/files/1043086/84720857106.pdf
- https://site-1039889.mozfiles.com/files/1039889/nipakiwumusitevoxosugime.pdf
- https://site-1040140.mozfiles.com/files/1040140/fuwafuxezelukitok.pdf
Embedded domains
- cctraff.ru
- tajurasexir.weebly.com
- fijojonibiw.weebly.com
- liwevapazu.weebly.com
- mogilifus.weebly.com
- uploads.strikinglycdn.com
- bedizegoresupa.weebly.com
- zimiduninu.weebly.com
- loguxofe.weebly.com
- fupexorugukemig.weebly.com
- site-1037177.mozfiles.com
- site-1043032.mozfiles.com
- site-1039828.mozfiles.com
- site-1040780.mozfiles.com
- site-1043289.mozfiles.com
- site-1040575.mozfiles.com
- site-1039492.mozfiles.com
- site-1043766.mozfiles.com
- site-1043086.mozfiles.com
- site-1039889.mozfiles.com
- site-1040140.mozfiles.com
- site-1044202.mozfiles.com
- site-1042347.mozfiles.com
- site-1036764.mozfiles.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report