MALICIOUS — notepalizinaroxer.pdf
MALICIOUS — notepalizinaroxer.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f2a69aeac1c304c94972363edb8d26bfb16fab69981636d02b20fa4c82039a45 - SHA-1:
399e443e50c01f42864e94cb82d220c76961dbcb - MD5:
c99a7358688c686af5471676096bff69 - ssdeep:
768:WgGzpDpetH5cTN69QvQSbV3Onq4tDQG06B5pM+0mhj:DGF9eYV3d4tDQG0c5m+0mhj - TLSH:
T16F316CF31057DC8C7ACB6F036DB6205D618AC74DA1229B600498772DD5BCAFD7E11A21 - Submitted as: notepalizinaroxer.pdf
- File type: pdf · Size: 40148 bytes
- Verdict: malicious (71/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/jatelu-zukolugaw.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=cuisinart+electric+ice+cream+maker+instructions, https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/xewuj.pdf, https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/1696278.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=cuisinart+electric+ice+cream+maker+instructions
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/xewuj.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/1696278.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/jatelu-zukolugaw.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/4e0d994f.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/rotizizalipi-xulejowo-wegevok-xutijub.pdf
- https://uploads.strikinglycdn.com/files/e626a9cd-8bdb-492b-9cdf-0db28ea45bc6/5003895992.pdf
- https://uploads.strikinglycdn.com/files/49ae475c-2c6e-4401-b734-3bab7f5265bc/82233218277.pdf
- https://uploads.strikinglycdn.com/files/49a29547-d2f1-4117-bc42-05b090025955/vevogefi.pdf
- https://uploads.strikinglycdn.com/files/c75389c2-9fff-4980-b9f7-6d2742e21b22/28052625789.pdf
- https://uploads.strikinglycdn.com/files/1bb686e1-e46a-4b09-b5b3-b8153ea51214/pojazeli.pdf
- https://cdn.shopify.com/s/files/1/0432/9259/0236/files/61048658450.pdf
- https://cdn.shopify.com/s/files/1/0486/4114/7038/files/lord_of_the_flies_chapter_8_quotes_explained.pdf
- https://cdn.shopify.com/s/files/1/0438/5603/5990/files/besoletigutevabikasabuj.pdf
- https://cdn.shopify.com/s/files/1/0488/4008/1573/files/my_airtel_app_free_download_for_android.pdf
- https://cdn.shopify.com/s/files/1/0497/4172/5857/files/51701640260.pdf
- https://site-1044106.mozfiles.com/files/1044106/gakejup.pdf
- https://site-1037124.mozfiles.com/files/1037124/bibowavopilesobuzoxujuj.pdf
- https://site-1043279.mozfiles.com/files/1043279/43727781459.pdf
- https://site-1043519.mozfiles.com/files/1043519/fotojil.pdf
- https://site-1039222.mozfiles.com/files/1039222/63736848983.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- bedizegoresupa.weebly.com
- vuxozajuje.weebly.com
- genigudepa.weebly.com
- fijojonibiw.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1044106.mozfiles.com
- site-1037124.mozfiles.com
- site-1043279.mozfiles.com
- site-1043519.mozfiles.com
- site-1039222.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report