MALICIOUS — bukinol.pdf
MALICIOUS — bukinol.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c0f53562c2ebab90d9e35dac778804f616fc57183c577ae637ad55ee55446881 - SHA-1:
31b393489ca12283f462e47deddd6efa42c2d3c5 - MD5:
dcc89bd5ea44fb4e66cc97a25693565d - ssdeep:
1536:bGF9pTmlISbrAP4u20BtQeQv7Wx0u/cqlHttpE7:6F9pTmlIN4u20BtXkg0u1Pi - TLSH:
T1AD348DF31097ED8CBA8FAB179DAA05A9A04AD3896136975014CC773CD4BC6EC7F01921 - Submitted as: bukinol.pdf
- File type: pdf · Size: 53198 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/3250b5961ed1.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=8086%20microprocessor%20programming%20tutorial%20.pdf, https://uploads.strikinglycdn.com/files/2799f4c7-6d0f-4708-80f2-e081064e97f4/pufimilorabu.pdf, https://uploads.strikinglycdn.com/files/77dae1ab-5014-43b0-81e6-6d5226641304/tajimijiwozukune.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=8086%20microprocessor%20programming%20tutorial%20.pdf
- https://s3.amazonaws.com/henghuili-files/35850964081.pdf
- https://s3.amazonaws.com/tesapibebujep/86392661161.pdf
- https://s3.amazonaws.com/tabobujimo/ralodawezivoxow.pdf
- https://uploads.strikinglycdn.com/files/2799f4c7-6d0f-4708-80f2-e081064e97f4/pufimilorabu.pdf
- https://uploads.strikinglycdn.com/files/77dae1ab-5014-43b0-81e6-6d5226641304/tajimijiwozukune.pdf
- https://uploads.strikinglycdn.com/files/8e444abc-a08f-48a0-9f52-47abdb443ec0/.pdf
- https://uploads.strikinglycdn.com/files/e843093a-86f0-4635-8401-0291d1d3d7d4/somiridilepesijukogul.pdf
- https://saxexowiki.weebly.com/uploads/1/3/0/9/130969873/loxujojotufonef-muselub.pdf
- https://nobinetezo.weebly.com/uploads/1/3/0/9/130969761/tupoxit.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/3250b5961ed1.pdf
- https://pevinuwipe.weebly.com/uploads/1/3/0/8/130873962/3530610.pdf
- https://uploads.strikinglycdn.com/files/7d8dac87-0b87-46f7-a7bb-6ecaf07f965b/las_leyes_de_newton_resumen.pdf
- https://uploads.strikinglycdn.com/files/ccc108d3-76fd-4e80-8a6c-fa5530d8012b/55112385676.pdf
- https://mijisurux.weebly.com/uploads/1/3/1/0/131070147/morogafogit_dopekotegafosu_mesozepavabop_sumoniwupuwen.pdf
- https://vujofuda.weebly.com/uploads/1/3/4/3/134375628/wosixojumem.pdf
- https://dunofedipusafo.weebly.com/uploads/1/3/4/4/134477286/7836361.pdf
- https://zegojipoxe.weebly.com/uploads/1/3/1/0/131069766/mabuw.pdf
- https://fixasamajiwige.weebly.com/uploads/1/3/4/3/134318971/dijakufesatedem.pdf
- https://cdn-cms.f-static.net/uploads/4367687/normal_5f8f9674267f3.pdf
- https://cdn-cms.f-static.net/uploads/4366306/normal_5f8718f7e5c82.pdf
- https://cdn-cms.f-static.net/uploads/4367925/normal_5f8f6165d569a.pdf
- https://cdn-cms.f-static.net/uploads/4401712/normal_5f92eb15934db.pdf
- https://cdn-cms.f-static.net/uploads/4366660/normal_5f87c559af45f.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- saxexowiki.weebly.com
- nobinetezo.weebly.com
- mojivimimujovo.weebly.com
- pevinuwipe.weebly.com
- mijisurux.weebly.com
- vujofuda.weebly.com
- dunofedipusafo.weebly.com
- zegojipoxe.weebly.com
- fixasamajiwige.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- N:\P(
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report