MALICIOUS — risufik_menisemu_nanapudaf.pdf
MALICIOUS — risufik_menisemu_nanapudaf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ef8b9998f1a4f327503ce824653423d78c40deb792959d787a999676cacc9ebc - SHA-1:
5aa09b9d2d5fe5af5cc4c6e907caefb50d8c46d5 - MD5:
968966916404630917c892cfee47abe4 - ssdeep:
768:MgGzpD6emq5LahgjHczEx9tx7Sc6POWHX3NRWPc5f5Bz5BlP9ph06ZRguPCxHB2:JGF2etfr2ctSX3NGc5fvp/Zauqz2 - TLSH:
T1D8327DF30097DD4C3E8BEF936AAB2458654ACB887132965404C8B76CC4BC6BD7F51A60 - Submitted as: risufik_menisemu_nanapudaf.pdf
- File type: pdf · Size: 45323 bytes
- Verdict: malicious (75/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://pimetagedipimop.weebly.com/uploads/1/3/1/6/131636886/8f7ca19905ed.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=louise%20hay%20libros%20gratis, https://pimetagedipimop.weebly.com/uploads/1/3/1/6/131636886/8f7ca19905ed.pdf, https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/6f984.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=louise%20hay%20libros%20gratis
- https://pimetagedipimop.weebly.com/uploads/1/3/1/6/131636886/8f7ca19905ed.pdf
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/6f984.pdf
- https://natizupasa.weebly.com/uploads/1/3/1/4/131437725/3138913.pdf
- https://cdn.shopify.com/s/files/1/0502/6637/4316/files/sosefolifefifu.pdf
- https://cdn.shopify.com/s/files/1/0438/4669/7122/files/27277637835.pdf
- https://uploads.strikinglycdn.com/files/a15471f3-7683-4431-beb4-6eef3ab7ad84/bopeduvixido.pdf
- https://uploads.strikinglycdn.com/files/f8f41de1-f5f4-41f5-9af1-2fb77f460860/33291834596.pdf
- https://cdn.shopify.com/s/files/1/0434/1130/8702/files/15571646390.pdf
- https://cdn.shopify.com/s/files/1/0438/6796/3557/files/65159078744.pdf
- https://cdn.shopify.com/s/files/1/0438/1225/7952/files/jamolufika.pdf
- https://cdn-cms.f-static.net/uploads/4365539/normal_5f881ad8f3da8.pdf
- https://cdn-cms.f-static.net/uploads/4368249/normal_5f88216974bc5.pdf
- https://cdn-cms.f-static.net/uploads/4367283/normal_5f88d8ef8dab9.pdf
- https://cdn-cms.f-static.net/uploads/4367922/normal_5f875ce452418.pdf
- https://uploads.strikinglycdn.com/files/1b4db451-1907-45d6-9393-a2effbcefeb5/86685557415.pdf
- https://uploads.strikinglycdn.com/files/7ac452d2-cd24-4ca1-8a9a-e889a1f45df3/19895903635.pdf
- https://uploads.strikinglycdn.com/files/c3ce7872-9201-4bf4-9245-28c9b4256010/nier_automata_yorha_betrayer.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- pimetagedipimop.weebly.com
- vilukenuxe.weebly.com
- natizupasa.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report