MALICIOUS — gofufalu_povixusevan_gudejeka_puvewa.pdf
MALICIOUS — gofufalu_povixusevan_gudejeka_puvewa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
97eb1308fb2f1590be8bd7d83948a6cd851586a2426317c4aaa0ad355cbbb990 - SHA-1:
4df2349012894e210a157a2228c3c39e64263334 - MD5:
ef24dab654233aa59b87ef7e9accafa6 - ssdeep:
768:cgGzpDepN0DtMXiFO1eojArjGK+tj6IqMDZFBfZjBKTE3NtOZMsQh:5GFypN0u6PrjGK+tjRDZFBfZjBKTGNtx - TLSH:
T1D3329EF35097DD4C7E8A9B036EAB11A9648AC38CB13697A4188D772CC0BC5BCAF55470 - Submitted as: gofufalu_povixusevan_gudejeka_puvewa.pdf
- File type: pdf · Size: 45584 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/9b924f.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=arihant%20idioms%20and%20phrases%20pdf%20download, https://uploads.strikinglycdn.com/files/92ed6a40-dd6e-4b66-b57d-b9ca20b401c2/dell_optiplex_9020_manual.pdf, https://uploads.strikinglycdn.com/files/024c550a-e7a7-4299-a42b-e58b6c904212/nuwiwujisesarevo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=arihant%20idioms%20and%20phrases%20pdf%20download
- https://uploads.strikinglycdn.com/files/92ed6a40-dd6e-4b66-b57d-b9ca20b401c2/dell_optiplex_9020_manual.pdf
- https://uploads.strikinglycdn.com/files/024c550a-e7a7-4299-a42b-e58b6c904212/nuwiwujisesarevo.pdf
- https://uploads.strikinglycdn.com/files/7316d868-9b91-4b46-b791-dc64a9c746b2/46209963697.pdf
- https://uploads.strikinglycdn.com/files/ac3428bb-a5d8-4fee-9a9d-f107c311b33a/yC3BCksek_gerilim_tekniC49Fi_ders_notlarC4B1.pdf
- https://leputixoted.weebly.com/uploads/1/3/2/6/132683438/votinodubibakax.pdf
- https://denasigetul.weebly.com/uploads/1/3/4/3/134332190/3933342.pdf
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/9b924f.pdf
- https://pimupaxepa.weebly.com/uploads/1/3/1/8/131857198/wexaxifup.pdf
- https://naxedomabaxa.weebly.com/uploads/1/3/1/6/131606472/7171184.pdf
- https://bilimetib.weebly.com/uploads/1/3/4/4/134435282/7088830.pdf
- https://cdn.shopify.com/s/files/1/0481/6676/4695/files/kamawiwavifomepabazazaduj.pdf
- https://cdn.shopify.com/s/files/1/0497/9238/5186/files/59182370319.pdf
- https://s3.amazonaws.com/zuxadol/mathematics_for_economists_carl_p._simon_lawrence_e._blume.pdf
- https://s3.amazonaws.com/gomakobez/filipino_recipes.pdf
- https://s3.amazonaws.com/wupixufekijax/5488424105.pdf
- https://s3.amazonaws.com/kigavanus/famoganejupifidudi.pdf
- https://cdn-cms.f-static.net/uploads/4369657/normal_5f8e6764b1c09.pdf
- https://cdn-cms.f-static.net/uploads/4384048/normal_5f8d46478a3e8.pdf
- https://cdn-cms.f-static.net/uploads/4385028/normal_5f96307c9b0cf.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- leputixoted.weebly.com
- denasigetul.weebly.com
- vilukenuxe.weebly.com
- pimupaxepa.weebly.com
- naxedomabaxa.weebly.com
- bilimetib.weebly.com
- cdn.shopify.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report