MALICIOUS — xufopekegamiwobiza.pdf
MALICIOUS — xufopekegamiwobiza.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9dc19fd34c4daf2e30547e2c1490ed62a9631e1ddb606dfe3b9b1eb1b5f70ac3 - SHA-1:
2eacb2a32ddbd8510cba3a77b44cbd0891403cd2 - MD5:
bb73ac4f6e1d731fd4ed93d794f77e3b - ssdeep:
768:EgGzpDtDfUTItI25fH7uhM8RhiAKp4rSchNl0R3BTdVxGe:xGF5gofdbD8nDK6hN233VxGe - TLSH:
T112329DF35497EC4CBA86AB439CBB14596196C3896233A7A054DC772DC0BC7BD7E40920 - Submitted as: xufopekegamiwobiza.pdf
- File type: pdf · Size: 46595 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/01b775ce-ca8e-45f9-9db7-f79a2ec627d3/wesis.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=aakash+aiats+question+papers+pdf, https://site-1036885.mozfiles.com/files/1036885/34211415767.pdf, https://site-1037096.mozfiles.com/files/1037096/54737235287.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=aakash+aiats+question+papers+pdf
- https://site-1036885.mozfiles.com/files/1036885/34211415767.pdf
- https://site-1037096.mozfiles.com/files/1037096/54737235287.pdf
- https://site-1037005.mozfiles.com/files/1037005/bisekaxosokugorufed.pdf
- https://uploads.strikinglycdn.com/files/dd3c2ecb-202d-4957-adb1-14fa3f1f3064/vudubapapugikatawopog.pdf
- https://uploads.strikinglycdn.com/files/0ad83c26-bceb-4b3d-9653-31f338794298/66687450842.pdf
- https://uploads.strikinglycdn.com/files/7dbfceb5-5b0d-4837-8796-5ca41feff078/rekofejalis.pdf
- https://uploads.strikinglycdn.com/files/01b775ce-ca8e-45f9-9db7-f79a2ec627d3/wesis.pdf
- https://uploads.strikinglycdn.com/files/6cf98074-421c-4966-b8a0-b88248e013bf/5825259933.pdf
- https://site-1037000.mozfiles.com/files/1037000/57066776035.pdf
- https://site-1036637.mozfiles.com/files/1036637/74069210837.pdf
- https://site-1037157.mozfiles.com/files/1037157/libemozuwodibovutaj.pdf
- https://site-1036772.mozfiles.com/files/1036772/fodoj.pdf
- https://site-1036864.mozfiles.com/files/1036864/23120892028.pdf
- https://uploads.strikinglycdn.com/files/89f11700-a0be-4f50-b602-fa87a7bd5f0c/50235846405.pdf
- https://uploads.strikinglycdn.com/files/04987bf0-f553-4cdb-a95a-41611d039eba/kaxopuguwejusibagawipe.pdf
- https://uploads.strikinglycdn.com/files/5d849957-7564-4311-bcdf-23e4778e0abe/78896661552.pdf
- https://uploads.strikinglycdn.com/files/91ce72f3-6a49-468e-a940-9e29fdd50ff5/jifimomogat.pdf
- https://uploads.strikinglycdn.com/files/c680a928-a2ea-4cc1-b5c9-6ea260d51fe2/silisagubufade.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1036885.mozfiles.com
- site-1037096.mozfiles.com
- site-1037005.mozfiles.com
- uploads.strikinglycdn.com
- site-1037000.mozfiles.com
- site-1036637.mozfiles.com
- site-1037157.mozfiles.com
- site-1036772.mozfiles.com
- site-1036864.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report