MALICIOUS — kevosefapinevo.pdf
MALICIOUS — kevosefapinevo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e440426509d9e95d3243e1cfdd2215719bc8a365f11a38ddfeb3d5d4002e1a00 - SHA-1:
76340d8f4db611527e37b9441759fc120922d0f4 - MD5:
32894f27877b98f3d55df6e64b55bc35 - ssdeep:
768:BgGzpD/p629POLJc+vXdkpZqwLKQthv1S0cODYJyHUmjN9xUwLdyV/:yGFjpuc+VCZneQtRaOD+yHUmjN9uwLI5 - TLSH:
T1E9328DF310A3ED8C7A8B6B439DE71595A58AD64D603793B01088776DC0BCAFD7E00662 - Submitted as: kevosefapinevo.pdf
- File type: pdf · Size: 46495 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/a7b88.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=book%20of%20regrets%20poe, https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/5650151.pdf, https://berajuvexoru.weebly.com/uploads/1/3/1/8/131860787/7911747.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=book%20of%20regrets%20poe
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/5650151.pdf
- https://berajuvexoru.weebly.com/uploads/1/3/1/8/131860787/7911747.pdf
- https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/kokobobe_bogaxusesewisel.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/a7b88.pdf
- https://rakamukomegu.weebly.com/uploads/1/3/2/6/132681656/20069.pdf
- https://cdn.shopify.com/s/files/1/0429/2398/3015/files/public_boulevard_crossword_answer.pdf
- https://uploads.strikinglycdn.com/files/b734df6e-edab-4b27-8a24-14c18771e130/31033080539.pdf
- https://uploads.strikinglycdn.com/files/1f309a89-718e-43d7-9ffb-90b6eae83ac4/37181476185.pdf
- https://uploads.strikinglycdn.com/files/4f3f8308-2fa7-4043-849a-d42eca97a66a/lemeduromevokoli.pdf
- https://uploads.strikinglycdn.com/files/ee66d40b-e3fd-44e8-ab47-62ddc4c5f2ea/53686071202.pdf
- https://uploads.strikinglycdn.com/files/0e08f7ca-0c2f-4269-976c-0a360e8d2b4e/supidijotemide.pdf
- https://site-1039140.mozfiles.com/files/1039140/wesofipetodop.pdf
- https://site-1037028.mozfiles.com/files/1037028/kudujugivu.pdf
- https://site-1043873.mozfiles.com/files/1043873/40132619635.pdf
- https://site-1041864.mozfiles.com/files/1041864/91640659215.pdf
- https://site-1039970.mozfiles.com/files/1039970/20612050723.pdf
- https://cdn.shopify.com/s/files/1/0432/5936/3496/files/79393034191.pdf
- https://cdn.shopify.com/s/files/1/0431/6174/7620/files/32532063389.pdf
- https://uploads.strikinglycdn.com/files/82d1afb0-c043-43a1-b562-6c1eb0117b27/tamolufunoju.pdf
- https://uploads.strikinglycdn.com/files/b356ba76-5549-466e-a887-e63ce24b18c9/fonomopep.pdf
- https://uploads.strikinglycdn.com/files/7c77c918-3f6a-4169-87a1-3cc40273fa79/33089677755.pdf
- https://uploads.strikinglycdn.com/files/9294161a-ab63-4569-ac7b-c45366e68a19/xejosev.pdf
- https://uploads.strikinglycdn.com/files/ca3f5882-e67b-4c1d-a52f-44092604c446/fafefamurazibuluf.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- jatorogerujew.weebly.com
- berajuvexoru.weebly.com
- walijogopabo.weebly.com
- gevafitasib.weebly.com
- rakamukomegu.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1039140.mozfiles.com
- site-1037028.mozfiles.com
- site-1043873.mozfiles.com
- site-1041864.mozfiles.com
- site-1039970.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report