MALICIOUS — bexikawuzidelutuje.pdf
MALICIOUS — bexikawuzidelutuje.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d61fba3b630fd0c1a3c20e2403757ff971f361fbb0bf4aac8b0bb1c60d815a75 - SHA-1:
ba51e462b3a2038cf818d5fbe4d0f576bf3a61b3 - MD5:
97a71f1440a1a9c6a06e82afaee60128 - ssdeep:
768:PgGzpDj7y6oR1hqRS8rJiVIFzrWx0eVTLptrbeYhWrQiW:4GFXz3wVTLpZb/hWrQiW - TLSH:
T1E1318DF35097DE8D3A879B436EA61599618AD3893033D7B0459C372CC0BC6AE6F40D61 - Submitted as: bexikawuzidelutuje.pdf
- File type: pdf · Size: 40065 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://vumorusumanipav.weebly.com/uploads/1/3/4/2/134234742/a34a93f5032.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=atomic%20structure%20worksheet%20answers%20pdf, https://jugubiwujivivej.weebly.com/uploads/1/3/4/3/134352954/2438005.pdf, https://vumorusumanipav.weebly.com/uploads/1/3/4/2/134234742/a34a93f5032.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=atomic%20structure%20worksheet%20answers%20pdf
- https://jugubiwujivivej.weebly.com/uploads/1/3/4/3/134352954/2438005.pdf
- https://vumorusumanipav.weebly.com/uploads/1/3/4/2/134234742/a34a93f5032.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/e56dd020.pdf
- https://uploads.strikinglycdn.com/files/34e6b36f-d758-4f87-a8fa-1f17b2e4b399/neopets_igloo_garage_sale_restock_guide.pdf
- https://nudopimiga.weebly.com/uploads/1/3/1/0/131070212/4023336.pdf
- https://cdn-cms.f-static.net/uploads/4377704/normal_5f966594c681d.pdf
- https://uploads.strikinglycdn.com/files/6a2971f7-1520-4559-9865-58dd838e43c3/49863338602.pdf
- https://cdn-cms.f-static.net/uploads/4392457/normal_5f911ee9946fc.pdf
- https://uploads.strikinglycdn.com/files/54e0b61d-9b03-41a3-88df-d7dacdc1d27f/pokizag.pdf
- https://besogedawifajop.weebly.com/uploads/1/3/4/2/134234635/0d66ab.pdf
- https://cdn.shopify.com/s/files/1/0427/8134/3903/files/historias_de_amor_gay.pdf
- https://cdn-cms.f-static.net/uploads/4370533/normal_5f8d54fdbdaa8.pdf
- https://cdn.shopify.com/s/files/1/0502/5749/4188/files/laxoworeraz.pdf
- https://tudupumodowi.weebly.com/uploads/1/3/1/4/131406798/49b86b5abb46524.pdf
- https://cdn-cms.f-static.net/uploads/4387819/normal_5f9abfb007f14.pdf
- https://cdn-cms.f-static.net/uploads/4379034/normal_5f8fa3610436b.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- jugubiwujivivej.weebly.com
- vumorusumanipav.weebly.com
- xojerajap.weebly.com
- uploads.strikinglycdn.com
- nudopimiga.weebly.com
- cdn-cms.f-static.net
- besogedawifajop.weebly.com
- cdn.shopify.com
- tudupumodowi.weebly.com
- www.w3.org
- purl.org
- brainplusiqs.com
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report