MALICIOUS — lutifidexaro.pdf
MALICIOUS — lutifidexaro.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c49794bd2388770cb2094bbe694f539798d3765e6c582fa622d5ddaab663a99c - SHA-1:
c5327ec0c2d99996fc6b668dc497ca797767f5ac - MD5:
feceeea801cb46ba4690f4974b8b66b6 - ssdeep:
768:8IgGzpDggJhEH+c0L/OUKOWsr1L/kZkblzQzVVgUmdAydxGYr6lC:8FGFcgXHUQBsszQzVViS2xGYr6lC - TLSH:
T189319DF340ABED8C7A86DB53AEAB24696449D78C61328A5005CC777CC47C6FDAF00A51 - Submitted as: lutifidexaro.pdf
- File type: pdf · Size: 41642 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/ebad0.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://trafftec.ru/wb?keyword=glencoe%20algebra%202%20worksheets%20answer%20key, https://cdn-cms.f-static.net/uploads/4413362/normal_5f9a035ebb433.pdf, https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/ebad0.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafftec.ru/wb?keyword=glencoe%20algebra%202%20worksheets%20answer%20key
- https://s3.amazonaws.com/zuxadol/66862022003.pdf
- https://cdn-cms.f-static.net/uploads/4413362/normal_5f9a035ebb433.pdf
- https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/ebad0.pdf
- https://cdn-cms.f-static.net/uploads/4372087/normal_5fa3f0fa7c3a2.pdf
- https://uploads.strikinglycdn.com/files/2f65c981-8479-4e2c-8ad6-c79cf745df0f/ripopexelifuwejami.pdf
- https://cdn-cms.f-static.net/uploads/4366374/normal_5f99442f614ba.pdf
- https://s3.amazonaws.com/nefagolom/vivid_seats_vs_stubhub_vs_ticketmaster.pdf
- https://uploads.strikinglycdn.com/files/4f8731c4-eb97-461b-92fd-7ceddbc98148/85695801009.pdf
- https://uploads.strikinglycdn.com/files/29eb8485-a465-41f6-b000-7d8c34274afc/42438765667.pdf
- https://cdn-cms.f-static.net/uploads/4365563/normal_5f87112237faf.pdf
- https://uploads.strikinglycdn.com/files/76ad8294-8573-4d09-b1c1-8e107d6d913a/35863214695.pdf
- https://cdn-cms.f-static.net/uploads/4448100/normal_5fa2c81491a60.pdf
- https://uploads.strikinglycdn.com/files/d63594b8-0d66-4e3d-9024-d406d4bbee09/faxexepabevage.pdf
- https://uploads.strikinglycdn.com/files/c036104f-0ffe-41a8-b2bd-7175667552f4/debetevafiga.pdf
- https://uploads.strikinglycdn.com/files/bf75e243-e52f-45e4-bf57-af8451e58c0c/sojigosemakaj.pdf
- https://cdn-cms.f-static.net/uploads/4368763/normal_5f904764a9bf2.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafftec.ru
- s3.amazonaws.com
- cdn-cms.f-static.net
- sepikupi.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report