MALICIOUS — dutoz_tixobegeloliwa.pdf
MALICIOUS — dutoz_tixobegeloliwa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f9529af902d91bba4248af9e4b8ab3bfbc47156146f0455f93b3f7bf0d194ee2 - SHA-1:
60ee86b8e17183402400a3f2e3dc1d5da5a4012e - MD5:
1298d10522f353fdd2a4fc7ecb05d424 - ssdeep:
768:wJgGzpDnpeYIlXrH2JZNYew+OYg+Lubk7ZT7hTuKC33M9pmm8K76:9GFTpVItKpOYgMH71oKUMPmmt76 - TLSH:
T144317CF350E7EC8C3A8B5B837DBB11AA618AC78821379750499C776DC57C6AC6F00990 - Submitted as: dutoz_tixobegeloliwa.pdf
- File type: pdf · Size: 42844 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/4008585.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=how%20i%20met%20your%20mother%20subtitulada, https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/4008585.pdf, https://sakukavazu.weebly.com/uploads/1/3/1/3/131379729/1780988.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=how%20i%20met%20your%20mother%20subtitulada
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/4008585.pdf
- https://sakukavazu.weebly.com/uploads/1/3/1/3/131379729/1780988.pdf
- https://fosogaji.weebly.com/uploads/1/3/1/4/131455903/virezati-wazovavo-guvumafaxibizer.pdf
- https://gomemetunugup.weebly.com/uploads/1/3/2/7/132712315/pezeduzadawu-xojixig.pdf
- https://uploads.strikinglycdn.com/files/b4aad126-9e30-4d0f-9ec3-31c504ad03e9/pyrex_professional_digital_thermometer_manual.pdf
- https://uploads.strikinglycdn.com/files/d8efd4b8-17bf-4c67-a124-a798f7183bfb/29912612041.pdf
- https://uploads.strikinglycdn.com/files/7512954d-ac6a-46b2-bc7e-7b53f1c7dafb/98444687883.pdf
- https://uploads.strikinglycdn.com/files/4991d970-cf12-4f0a-ab17-068e4611a585/gaxugakonefokigiveto.pdf
- https://uploads.strikinglycdn.com/files/096471f6-4ac3-4298-ac4f-b504dec84ce5/9775504846.pdf
- https://uploads.strikinglycdn.com/files/476798eb-a8b8-4916-b145-fa7f872d090d/56001526343.pdf
- https://uploads.strikinglycdn.com/files/ea81a23c-0ed0-4750-ab13-3bcded0c9708/49185965365.pdf
- https://uploads.strikinglycdn.com/files/4d00b88d-3c37-43c1-8c62-070885fc6774/kejolivirizepi.pdf
- https://natizupasa.weebly.com/uploads/1/3/1/4/131437725/mobukik_kawumemux_jutexenefukefab_xurituj.pdf
- https://nurekagenarufab.weebly.com/uploads/1/3/1/6/131636906/1168738.pdf
- https://wesujugureju.weebly.com/uploads/1/3/0/8/130874517/01df29aaafbfa.pdf
- https://kilejotiwig.weebly.com/uploads/1/3/1/4/131406519/bf39f60ee.pdf
- https://cdn.shopify.com/s/files/1/0478/0900/3687/files/pifavaner.pdf
- https://cdn.shopify.com/s/files/1/0481/5464/0533/files/83533406592.pdf
- https://cdn.shopify.com/s/files/1/0484/8392/6171/files/app_to_fix_red_eye_android.pdf
- https://cdn.shopify.com/s/files/1/0497/5699/5745/files/vosagirawufupalojokupa.pdf
- https://cdn.shopify.com/s/files/1/0484/0888/7453/files/cambio_climatico_2020.pdf
- https://cdn.shopify.com/s/files/1/0499/9725/0711/files/stryker_gamma_nail_technique_guide.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- jufaxexave.weebly.com
- sakukavazu.weebly.com
- fosogaji.weebly.com
- gomemetunugup.weebly.com
- uploads.strikinglycdn.com
- natizupasa.weebly.com
- nurekagenarufab.weebly.com
- wesujugureju.weebly.com
- kilejotiwig.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report