MALICIOUS — dewabewe.pdf
MALICIOUS — dewabewe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d43db385957778c080c8dcef2587ad10228a7c12cebdb7e3402e7c8da0086deb - SHA-1:
60053e9a17df96a710021aeb9e8ecb4bf3f50f8d - MD5:
a42e3ef53944a5ee876742035aa8432c - ssdeep:
3072:+6qLI3+bRsiCXmmGs2MZI5BfwfSLZ/gP9THIlv4uv4I/xGGo/cSq889RbyT:+6+NdkXmi2Y6fdgFTHIlFgtGhR2 - TLSH:
T10F3F02F321D3DE8C7983EF13B8AA6414B485D39431726B208188B6ADC97D75CBD91E21 - Submitted as: dewabewe.pdf
- File type: pdf · Size: 153343 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://mifurujuxix.weebly.com/uploads/1/3/3/9/133997148/7dd34181396bb.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gimoguvi.ru/wb?keyword=attack%20on%20titan%20anime%20story%20so%20far, https://mifurujuxix.weebly.com/uploads/1/3/3/9/133997148/7dd34181396bb.pdf, https://lexezidelaxo.weebly.com/uploads/1/3/4/6/134605078/pomigoxigazimugare.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gimoguvi.ru/wb?keyword=attack%20on%20titan%20anime%20story%20so%20far
- https://mifurujuxix.weebly.com/uploads/1/3/3/9/133997148/7dd34181396bb.pdf
- https://s3.amazonaws.com/fomudebipefasu/androidx_constraintlayout_not_working.pdf
- https://s3.amazonaws.com/bededuxotulapil/poweredge_r710_memory_guide.pdf
- https://lexezidelaxo.weebly.com/uploads/1/3/4/6/134605078/pomigoxigazimugare.pdf
- http://universe1.space/95030658255w0zpm.pdf
- https://uploads.strikinglycdn.com/files/d2290505-8f4f-42a8-b18c-c95053141dd9/what_streaming_service_has_wolf_of_wall_street.pdf
- https://e5baaea7-7007-41de-9367-4ebf3ed55875.filesusr.com/ugd/8e1900_5d4da42117f948a294e29b7def4ce880.pdf?index=true
- http://latuha.com/unsettled_tom_meme_templateoohs2.pdf
- https://8e0cabef-d481-4215-b437-8a5fc4e4723c.filesusr.com/ugd/f41140_cdb38dbda8604047b17d569cb401f6ab.pdf?index=true
- https://6d4cd3b7-91e9-43ac-92b9-205473f1e50d.filesusr.com/ugd/28146e_cdbbf73b51514211a504c3b2b3d6ea23.pdf?index=true
- https://zetodimamewiwek.weebly.com/uploads/1/3/2/3/132302859/7695636.pdf
- https://uploads.strikinglycdn.com/files/76f7d2f6-84c1-463c-a6bf-26e3c2a66aa2/much_ado_about_nothing_analysis_act_1_scene_2.pdf
- https://s3.amazonaws.com/dapekufoxiraku/becoming_raw_vegan.pdf
- https://wotilawijuv.weebly.com/uploads/1/3/4/8/134852567/2941c9ed6facb9e.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gimoguvi.ru
- mifurujuxix.weebly.com
- s3.amazonaws.com
- lexezidelaxo.weebly.com
- universe1.space
- uploads.strikinglycdn.com
- e5baaea7-7007-41de-9367-4ebf3ed55875.filesusr.com
- latuha.com
- 8e0cabef-d481-4215-b437-8a5fc4e4723c.filesusr.com
- 6d4cd3b7-91e9-43ac-92b9-205473f1e50d.filesusr.com
- zetodimamewiwek.weebly.com
- wotilawijuv.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report