MALICIOUS — fulaminifusatiravup.pdf
MALICIOUS — fulaminifusatiravup.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f026850ecb1291280243cabb74868b21f88b58bd9761689902ce4bc2cbfcc5dd - SHA-1:
203adc7808be21d1a491fb8e87e0882c9ac333d6 - MD5:
141827272f4eba2bb6d3e9e781e124f2 - ssdeep:
1536:0j1rgMS5F/lXRSuMALopSDRUbyo0UNsdtahIUS40TMbcgjtuVvlyB4SmrhWmolNJ:i10MShRSul0p92o0UNsdtaBSTT0jtWlW - TLSH:
T1CF38DFF36157DD8C379A6B1779D728587489D2882032EB502488B72C8DBC6FE6F20E51 - Submitted as: fulaminifusatiravup.pdf
- File type: pdf · Size: 77465 bytes
- Verdict: malicious (75/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/3b984365-1ee8-435a-ae83-827e04e499ac/doxawituditag.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://trafffe.ru/strik?utm_term=subwoofer+bass+pro+apk+cracked, https://kofemadaki.weebly.com/uploads/1/3/4/6/134675418/23865b0e.pdf, https://cdn.sqhk.co/linerutinew/Ejhb1GY/all_star_smash_mouth_drum_tab.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffe.ru/strik?utm_term=subwoofer+bass+pro+apk+cracked
- https://kofemadaki.weebly.com/uploads/1/3/4/6/134675418/23865b0e.pdf
- https://cdn.sqhk.co/linerutinew/Ejhb1GY/all_star_smash_mouth_drum_tab.pdf
- https://zejebamusij.weebly.com/uploads/1/3/2/3/132302936/vodurejabivob.pdf
- https://uploads.strikinglycdn.com/files/b8bb96cc-9f8f-4d62-b216-fb22e4b0ce95/vejawubibelamuwuladuturo.pdf
- https://wugaxaxelapuwu.weebly.com/uploads/1/3/4/5/134595152/601404.pdf
- https://uploads.strikinglycdn.com/files/65f31b61-ae34-47ab-93d0-d5afd6432676/piputuvavurakevi.pdf
- https://lokugejepotag.weebly.com/uploads/1/3/4/3/134318746/8720332.pdf
- https://tubumafipe.weebly.com/uploads/1/3/4/4/134458357/3114525.pdf
- https://uploads.strikinglycdn.com/files/3b984365-1ee8-435a-ae83-827e04e499ac/doxawituditag.pdf
- https://uploads.strikinglycdn.com/files/e6c28878-59e8-4600-9c5f-f4661328b01c/308149858.pdf
- https://cdn.sqhk.co/sofaxuleruri/eUgciaQ/52167721550.pdf
- https://uploads.strikinglycdn.com/files/fc5db790-6751-45be-861b-0e3485294431/the_gender_secret_series.pdf
- https://sudesiresa.weebly.com/uploads/1/3/4/8/134881981/84a63493b1e4.pdf
- https://uploads.strikinglycdn.com/files/d39ba070-1490-4f31-a1a3-aca055ee14a6/najifezo.pdf
- https://nimizinimaji.weebly.com/uploads/1/3/4/7/134703428/1370f.pdf
- https://uploads.strikinglycdn.com/files/ec1f5d09-f215-40a6-8a3d-7f9be82c64d9/idiots_guide_to_buddhism.pdf
- https://cdn.sqhk.co/zifalulog/RELGxpi/golden_goal_sports_park_ny.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffe.ru
- kofemadaki.weebly.com
- cdn.sqhk.co
- zejebamusij.weebly.com
- uploads.strikinglycdn.com
- wugaxaxelapuwu.weebly.com
- lokugejepotag.weebly.com
- tubumafipe.weebly.com
- sudesiresa.weebly.com
- nimizinimaji.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report