MALICIOUS — sisosefutavif-kakinenosa-wetedawum.pdf
MALICIOUS — sisosefutavif-kakinenosa-wetedawum.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b8cd2bd4eba3e9fdbe4f4c8be0af03b667b52906a5268a99039b905063bb417d - SHA-1:
7e976ddbc898ea8434c35b58471e9487ce1a5252 - MD5:
fbe7b6cd96a2a751ecfb3dc7e6ad3337 - ssdeep:
768:IgGzpDKp2h+gwS6tSZtCk4LUAsb/rwotX9dqF9Jmpf9bi:FGF2prSeItC14tTwetdqrJmpf9bi - TLSH:
T1D5318DF7209BDC8C7FCA5B03A97B115A5089D388A137EB5408DCB76DC47C6AD6E00961 - Submitted as: sisosefutavif-kakinenosa-wetedawum.pdf
- File type: pdf · Size: 42935 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/tiladejonu.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=pdf%20reader%20apk%20download%20latest%20version, https://cdn.shopify.com/s/files/1/0431/9235/2928/files/vofurapukiginurenat.pdf, https://cdn.shopify.com/s/files/1/0502/8282/3852/files/fulirewovetutugi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=pdf%20reader%20apk%20download%20latest%20version
- https://cdn.shopify.com/s/files/1/0431/9235/2928/files/vofurapukiginurenat.pdf
- https://cdn.shopify.com/s/files/1/0502/8282/3852/files/fulirewovetutugi.pdf
- https://cdn.shopify.com/s/files/1/0429/2411/4076/files/michael_cohen_meme.pdf
- https://xozoravupot.weebly.com/uploads/1/3/4/3/134314106/gujilizukan.pdf
- https://pesajupamobe.weebly.com/uploads/1/3/1/6/131607203/litovivof_sijomidigeza_favusanoti_nabiwemed.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/tiladejonu.pdf
- https://s3.amazonaws.com/vufupu/salikuvuwozol.pdf
- https://s3.amazonaws.com/gupuso/third_eye_opening_secrets.pdf
- https://runebipunozup.weebly.com/uploads/1/3/1/4/131406604/lorukeje-famipumeremud-rubagipiv.pdf
- https://riwisasivituw.weebly.com/uploads/1/3/1/0/131070703/7909875.pdf
- https://zelapagetuwuj.weebly.com/uploads/1/3/1/4/131406140/dozemu.pdf
- https://gobisenuginofaz.weebly.com/uploads/1/3/4/4/134490447/gigabap_xawixugoxujexeb_woluv_ralotoruzegu.pdf
- https://zekasujiminog.weebly.com/uploads/1/3/4/3/134366003/zidejeme_surujelagedide_dokatamekod_kofawuk.pdf
- https://zavegaligap.weebly.com/uploads/1/3/4/4/134499553/buzazupumoridufug.pdf
- https://zalawevovupat.weebly.com/uploads/1/3/0/9/130969727/85c64d55f.pdf
- https://buximinolid.weebly.com/uploads/1/3/1/3/131381316/11cfb56f821c652.pdf
- https://uploads.strikinglycdn.com/files/a7e0471e-2deb-401c-8913-462c825b94ad/nutritional_supplements_book_lyle_macwilliam.pdf
- https://uploads.strikinglycdn.com/files/182a15ce-d2c5-42ea-b124-0cf34e0b7f92/potavoseku.pdf
- https://uploads.strikinglycdn.com/files/1896f3ed-4389-43f6-b433-4babab7497bc/fopoxufukoripufuj.pdf
- https://uploads.strikinglycdn.com/files/8d553c56-07b2-4e52-9a10-79a7f60d2617/lemanirisudeluxawe.pdf
- https://uploads.strikinglycdn.com/files/d14cf30e-fb20-4ed9-8087-5ad7144bfe49/viva_la_vape_instructions.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- xozoravupot.weebly.com
- pesajupamobe.weebly.com
- guwomenod.weebly.com
- s3.amazonaws.com
- runebipunozup.weebly.com
- riwisasivituw.weebly.com
- zelapagetuwuj.weebly.com
- gobisenuginofaz.weebly.com
- zekasujiminog.weebly.com
- zavegaligap.weebly.com
- zalawevovupat.weebly.com
- buximinolid.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report