MALICIOUS — sukojiz_leludebasitov_riwatexopixo_joteligaj.pdf
MALICIOUS — sukojiz_leludebasitov_riwatexopixo_joteligaj.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a94a927675a2591cfa2a2cd1aaf067ca27beee49a7f1561acd0326906030b9a3 - SHA-1:
37232be0368e440724c06da9fba0885f70793718 - MD5:
15a4ba9b90fdb1cacf45d19a8f0f54f8 - ssdeep:
768:6gGzpDGpJkJP3gffAbAnbjUqftpF/Xk+NYfLuh6ZHIxFGQI9IhgCtGDA:nGFKpvF/T169IbGQIOVGDA - TLSH:
T179327DF35097EC4C7A8B6B039DA71196A08ED3497137E760158CB72DE8AC5BE7E50820 - Submitted as: sukojiz_leludebasitov_riwatexopixo_joteligaj.pdf
- File type: pdf · Size: 44261 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jizonuwuko.weebly.com/uploads/1/3/0/8/130814311/duretazejoso.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=what%20is%20swabi%20in%20grammar, https://tubenuluni.weebly.com/uploads/1/3/1/4/131437864/batezumezesaragimil.pdf, https://jizonuwuko.weebly.com/uploads/1/3/0/8/130814311/duretazejoso.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=what%20is%20swabi%20in%20grammar
- https://tubenuluni.weebly.com/uploads/1/3/1/4/131437864/batezumezesaragimil.pdf
- https://jizonuwuko.weebly.com/uploads/1/3/0/8/130814311/duretazejoso.pdf
- https://tiwilofudux.weebly.com/uploads/1/3/1/6/131606348/020fbba5fb.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/e27909d0be.pdf
- https://kekerisasil.weebly.com/uploads/1/3/0/7/130775365/2550438.pdf
- https://uploads.strikinglycdn.com/files/79a09ca3-a37c-4a4e-86ab-f280919729f4/contratos_para_eventos.pdf
- https://uploads.strikinglycdn.com/files/143c365e-c997-42c3-bc5f-d3d452f0dfdd/66345046575.pdf
- https://uploads.strikinglycdn.com/files/557dac7b-d896-4d87-8de8-2ca7398d7d64/wazowewu.pdf
- https://vopevejefed.weebly.com/uploads/1/3/1/6/131606133/duledixefubo.pdf
- https://pevinuwipe.weebly.com/uploads/1/3/0/8/130873962/bixuxuligulikurebav.pdf
- https://xanodupujariris.weebly.com/uploads/1/3/0/9/130969381/sadokuxarezug.pdf
- https://degujipimisa.weebly.com/uploads/1/3/1/4/131453395/9864572.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/batagebexi.pdf
- https://cdn-cms.f-static.net/uploads/4365635/normal_5f874300b1dbb.pdf
- https://cdn-cms.f-static.net/uploads/4367299/normal_5f87d36b111e3.pdf
- https://cdn-cms.f-static.net/uploads/4370090/normal_5f8ce190e00e7.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f86f4a6ae4d5.pdf
- https://cdn-cms.f-static.net/uploads/4366637/normal_5f87204260238.pdf
- https://cdn.shopify.com/s/files/1/0499/3210/7937/files/construction_safety_signage.pdf
- https://cdn.shopify.com/s/files/1/0502/4441/9757/files/net_tv_plus_app_android.pdf
- https://cdn.shopify.com/s/files/1/0502/2466/0664/files/xexavapuditadas.pdf
- https://cdn.shopify.com/s/files/1/0462/8463/6320/files/frp_bypass_android_7.0_tablet.pdf
- https://cdn.shopify.com/s/files/1/0434/6386/8573/files/ziwinixuzoror.pdf
- https://cdn.shopify.com/s/files/1/0496/6980/0089/files/44181137423.pdf
Embedded domains
- cctraff.ru
- tubenuluni.weebly.com
- jizonuwuko.weebly.com
- tiwilofudux.weebly.com
- gevafitasib.weebly.com
- kekerisasil.weebly.com
- uploads.strikinglycdn.com
- vopevejefed.weebly.com
- pevinuwipe.weebly.com
- xanodupujariris.weebly.com
- degujipimisa.weebly.com
- mojivimimujovo.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report