MALICIOUS — fegerexebifemuzoga.pdf
MALICIOUS — fegerexebifemuzoga.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e647099f60935e671a4e39b6a08f871476c8d1f950aa68d6b5211842801064f7 - SHA-1:
02613fbc478c208de2b1e01b69b47557b83d87c4 - MD5:
1728f114e340eb09ae3ccc1c9b5d26d0 - ssdeep:
1536:cJlvm4waz/3Pz5d0ZdTXWXDDnkBGqULjTmbqzDFnHdUElViksMdZK3NAk:+wazv96ZdTOCb+pnHeE5Ddc3d - TLSH:
T1F638D1B34257FD8CB995AB137AB50668B54D938C71329BA40484F76CC8FCAAE2F10550 - Submitted as: fegerexebifemuzoga.pdf
- File type: pdf · Size: 78617 bytes
- Verdict: malicious (75/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!1728F114E340
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4462992/normal_5ffcc5c8bbf21.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://traffmen.ru/wb?keyword=hot%20rod%20kit%20car%20uk, https://static.s123-cdn-static.com/uploads/4496853/normal_5ff3b637b373c.pdf, https://site-1241989.mozfiles.com/files/1241989/95158921703.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffmen.ru/wb?keyword=hot%20rod%20kit%20car%20uk
- https://static.s123-cdn-static.com/uploads/4496853/normal_5ff3b637b373c.pdf
- https://site-1241989.mozfiles.com/files/1241989/95158921703.pdf
- https://site-1168207.mozfiles.com/files/1168207/25562240684.pdf
- https://cdn-cms.f-static.net/uploads/4365546/normal_5f8fa4f28011b.pdf
- https://cdn-cms.f-static.net/uploads/4421970/normal_5fc29fe45b6e5.pdf
- https://static.s123-cdn-static.com/uploads/4462992/normal_5ffcc5c8bbf21.pdf
- https://static.s123-cdn-static.com/uploads/4500887/normal_5ff97c289cc8c.pdf
- https://static.s123-cdn-static.com/uploads/4464878/normal_5fc6daa7079d9.pdf
- https://cdn-cms.f-static.net/uploads/4498702/normal_5fb293fa3507b.pdf
- https://site-1179856.mozfiles.com/files/1179856/my_car_run_hot_but_not_overheating.pdf
- https://site-1178057.mozfiles.com/files/1178057/78187857571.pdf
- https://cdn-cms.f-static.net/uploads/4374956/normal_5f9420ee29f37.pdf
- https://cdn.sqhk.co/vekuperik/ifjc3ha/pico_iyer_quotes.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffmen.ru
- static.s123-cdn-static.com
- site-1241989.mozfiles.com
- site-1168207.mozfiles.com
- cdn-cms.f-static.net
- site-1179856.mozfiles.com
- site-1178057.mozfiles.com
- cdn.sqhk.co
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report