MALICIOUS — tevob.pdf
MALICIOUS — tevob.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
dc9daaa6995f052c2a01977ab6460639cecffed40c597ab6ee83ec142df4e408 - SHA-1:
5290b01cda4b5cb4b0591af007b7408cdfbf8ba7 - MD5:
becaa8683f758ac07985940a4c250e86 - ssdeep:
768:6gGzpDwpQT70sM6NoaHHzWIsUgXrpQ389Q6UleB9FD:nGFcpNsMMoazWIcdQ389ieB9FD - TLSH:
T1AE306DF310A7DD4CBA8F6B07ADEB119A558FC38C613793A05998372DC47C2ADAD10861 - Submitted as: tevob.pdf
- File type: pdf · Size: 38172 bytes
- Verdict: malicious (71/100)
Detections (2 of 50 engines)
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://fulipevaxavu.weebly.com/uploads/1/3/2/6/132695351/80362e9c7c.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=meth%20equals%20sorcery%20book, https://sepenunaxob.weebly.com/uploads/1/3/0/7/130776074/webolido.pdf, https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/xegozuxelat_volet_namamubefajoze_vixore.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=meth%20equals%20sorcery%20book
- https://sepenunaxob.weebly.com/uploads/1/3/0/7/130776074/webolido.pdf
- https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/xegozuxelat_volet_namamubefajoze_vixore.pdf
- https://noxepelobisuse.weebly.com/uploads/1/3/1/8/131871648/wikemagebagimamaruki.pdf
- https://rakamukomegu.weebly.com/uploads/1/3/2/6/132681656/joralazokeke.pdf
- https://fulipevaxavu.weebly.com/uploads/1/3/2/6/132695351/80362e9c7c.pdf
- https://site-1038565.mozfiles.com/files/1038565/pidirodelamipozajoxitenod.pdf
- https://site-1040224.mozfiles.com/files/1040224/45122188895.pdf
- https://uploads.strikinglycdn.com/files/af69bb90-e40a-4368-9b7d-977aff7b8e60/judefopavuveseramo.pdf
- https://uploads.strikinglycdn.com/files/1e01d30c-b847-4d0f-948e-c636d2cd2aed/11849953838.pdf
- https://uploads.strikinglycdn.com/files/54110f26-b97b-4aa4-b928-4a2430e1b21d/navinowikudon.pdf
- https://uploads.strikinglycdn.com/files/c151c037-247c-46c2-ac35-980e447d0fe8/xejenorisos.pdf
- https://site-1042014.mozfiles.com/files/1042014/rapomazonojuda.pdf
- https://site-1042918.mozfiles.com/files/1042918/pabavinodokus.pdf
- https://site-1037176.mozfiles.com/files/1037176/3728350027.pdf
- https://site-1038391.mozfiles.com/files/1038391/39414289495.pdf
- https://site-1048265.mozfiles.com/files/1048265/trail_tech_vapor_install_instructions.pdf
- https://uploads.strikinglycdn.com/files/917e0c11-737d-4a3f-a38d-81bacecd5fc1/danutazagizapevudalijur.pdf
- https://uploads.strikinglycdn.com/files/e55efeec-ab11-4bf5-b25b-3aca526f693d/76708646334.pdf
- https://uploads.strikinglycdn.com/files/3a2e9f29-3491-4a24-ab2a-73de1056903a/92635131138.pdf
- https://uploads.strikinglycdn.com/files/7f06d548-8630-4288-b9ed-17c7242043d6/16825932467.pdf
- https://uploads.strikinglycdn.com/files/58a54b8a-dcb0-4eaa-80fe-9440dd385846/wameniruporukiwiwepoje.pdf
- https://uploads.strikinglycdn.com/files/9414e972-1902-4463-8524-8a4b8ff9f636/gaposezekusadalerom.pdf
- https://uploads.strikinglycdn.com/files/4c915f71-949e-43e5-a103-c720b399f60c/xiwasurejupagabe.pdf
- https://uploads.strikinglycdn.com/files/fc067b6c-72d7-4bde-baaa-58299c723a4b/gewufotimipuwubulesaw.pdf
Embedded domains
- ggtraff.ru
- sepenunaxob.weebly.com
- sepikupi.weebly.com
- noxepelobisuse.weebly.com
- rakamukomegu.weebly.com
- fulipevaxavu.weebly.com
- site-1038565.mozfiles.com
- site-1040224.mozfiles.com
- uploads.strikinglycdn.com
- site-1042014.mozfiles.com
- site-1042918.mozfiles.com
- site-1037176.mozfiles.com
- site-1038391.mozfiles.com
- site-1048265.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report