MALICIOUS — lekozuwaniw.pdf
MALICIOUS — lekozuwaniw.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e6afc9255859056f724498c957b5fbd7cec52b13109f6200bd4191acf0eeb341 - SHA-1:
35eba8160501e2225ee77e691aadfedac42f8195 - MD5:
99e3e75cb4c54eb2a080dd774086d62e - ssdeep:
768:hgGzpD4p7PC3nGMPyf7f3COQr9+tLi9Yyf1u3Pd+6GmWjoUdOVp:SGFcppPClr9z9ff10+6GPoPp - TLSH:
T19D319EF310A7EC4C6ACBAB136DAB119E654AC78C6137D3A055C9772CC4BC5BCAE11920 - Submitted as: lekozuwaniw.pdf
- File type: pdf · Size: 40611 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/9668666.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=guardian%20drama%20vostfr, https://cdn.shopify.com/s/files/1/0484/9588/6486/files/xefewulutuli.pdf, https://cdn.shopify.com/s/files/1/0433/5573/4167/files/japanese_bed_frame_king.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=guardian%20drama%20vostfr
- https://cdn.shopify.com/s/files/1/0484/9588/6486/files/xefewulutuli.pdf
- https://cdn.shopify.com/s/files/1/0433/5573/4167/files/japanese_bed_frame_king.pdf
- https://cdn.shopify.com/s/files/1/0498/7577/9742/files/60578999689.pdf
- https://cdn.shopify.com/s/files/1/0497/9081/2322/files/rulavuvitijib.pdf
- https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/9668666.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/2245757.pdf
- https://riwisasivituw.weebly.com/uploads/1/3/1/0/131070703/7373486.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/7304884.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/32e063a95e.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/xewuj.pdf
- https://cdn.shopify.com/s/files/1/0485/1954/4987/files/table_tanks_2_unblocked.pdf
- https://cdn.shopify.com/s/files/1/0430/5197/4818/files/detagarozeboxekunosowox.pdf
- https://tipefejiri.weebly.com/uploads/1/3/0/9/130969755/buwobu.pdf
- https://xanodupujariris.weebly.com/uploads/1/3/0/9/130969381/9f9194124b1b.pdf
- https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/9325577.pdf
- https://xumogimunosu.weebly.com/uploads/1/3/1/6/131607683/jofamep_xevozurenatef.pdf
- https://site-1039883.mozfiles.com/files/1039883/7334110044.pdf
- https://site-1040987.mozfiles.com/files/1040987/78489274731.pdf
- https://site-1048482.mozfiles.com/files/1048482/85276150958.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- jukafubu.weebly.com
- vozunutav.weebly.com
- riwisasivituw.weebly.com
- genigudepa.weebly.com
- keniwuki.weebly.com
- bedizegoresupa.weebly.com
- tipefejiri.weebly.com
- xanodupujariris.weebly.com
- jiwepurojal.weebly.com
- xumogimunosu.weebly.com
- site-1039883.mozfiles.com
- site-1040987.mozfiles.com
- site-1048482.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report