MALICIOUS — kuratopajegiguk-firikiveduxe-dejugufuso-xadugopu.pdf
MALICIOUS — kuratopajegiguk-firikiveduxe-dejugufuso-xadugopu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bbdcc7f33a7c0206d7ebf8905c33683d3a762de2708f17f48c46933d5ca9f1d4 - SHA-1:
a357cfad19cd2e8ca54869e6a8556b6fddce9aa3 - MD5:
14e7c3ed3db7a0e813d7bd9f3ebd5c83 - ssdeep:
1536:ZFGR2r8kbo2pNeJvaZ3SY0T+WKHZ9yuD2j+ASGPi2rurtgqswEVxr1:WRY8kNOGCY0vKmro2wEV/ - TLSH:
T11336D0F394DBDC4C7A9B9B037FEA18596086C7886033E7560CC83A6C80BC9BD2D14A55 - Submitted as: kuratopajegiguk-firikiveduxe-dejugufuso-xadugopu.pdf
- File type: pdf · Size: 69558 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://static1.squarespace.com/static/5fc2acbdbda9c57a97c99165/t/5fcb17ae7ab0f364aba68fa4/1607145391389/41197147586.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://trafffe.ru/wb?keyword=full%20movie%20%20site%20for%20pc, https://static1.squarespace.com/static/5fc2acbdbda9c57a97c99165/t/5fcb17ae7ab0f364aba68fa4/1607145391389/41197147586.pdf, https://static1.squarespace.com/static/5fc65124df132613bbe271c4/t/5fd6538296ed101a3e3e0799/1607881603095/junulabajezo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffe.ru/wb?keyword=full%20movie%20%20site%20for%20pc
- https://static1.squarespace.com/static/5fc2acbdbda9c57a97c99165/t/5fcb17ae7ab0f364aba68fa4/1607145391389/41197147586.pdf
- https://static1.squarespace.com/static/5fc65124df132613bbe271c4/t/5fd6538296ed101a3e3e0799/1607881603095/junulabajezo.pdf
- https://zifuxiwow.weebly.com/uploads/1/3/3/9/133997311/4074054.pdf
- https://static1.squarespace.com/static/5fc185bea8793968640cb600/t/5fc45cb14f983757206acade/1606704305692/dbt_tipp_skills.pdf
- https://static1.squarespace.com/static/5fc1b3a916f6d44b07c461c5/t/5fcb80c49d29b56e4d032aaa/1607172299349/god_kings_game_wiki.pdf
- https://static1.squarespace.com/static/5fbffea5239b0722912c2f3a/t/5fc442724f9837572066e06f/1606697587111/zinuninaviwi.pdf
- https://static1.squarespace.com/static/5fc55a1324b06a7eb31d25e2/t/5fcbe96db6b7366152070032/1607199086385/street_fighter_4_or_super_street_fighter_4.pdf
- https://static1.squarespace.com/static/5fc77e28382bec7399f7cbaf/t/5fcd3056d235d37878cfd333/1607282774281/xbox_series_x_release_date_uk_stock.pdf
- https://static1.squarespace.com/static/5fc2b45ca87939686413d8d4/t/5fc7eaa69c2e343139b7cb5a/1606937259213/jasumofovozis.pdf
- https://cdn-cms.f-static.net/uploads/4390660/normal_5fbc58fcd10d3.pdf
- https://static1.squarespace.com/static/5fc592c8239b07229150fbb5/t/5fcbb8906fd93023bc0bcdab/1607186577218/7998049447.pdf
- https://static1.squarespace.com/static/5fc2bfbc2cf09257bd77efeb/t/5fc65b0b61e25426e111020d/1606834955484/teaching_strategies_gold_training_powerpoint.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbd022ec7afe470b5571fa7/1606222386844/vurenenanevokasekof.pdf
- https://static1.squarespace.com/static/5fc5c4adc89e1c4b8fdffd23/t/5fc7392d8f07963615766f0a/1606891821729/vertical_packing_machine.pdf
- https://tumixivig.weebly.com/uploads/1/3/1/6/131636813/rawefo.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe0b1c1972c46e3c666fb2/1606290204960/razas_de_conejos.pdf
- https://static1.squarespace.com/static/5fc784e68651a0475198618b/t/5fd04b84a91a8d243376835a/1607486340770/91413755420.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffe.ru
- static1.squarespace.com
- zifuxiwow.weebly.com
- cdn-cms.f-static.net
- tumixivig.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report