MALICIOUS — borawixis-kegeluruxakij-jabofu.pdf
MALICIOUS — borawixis-kegeluruxakij-jabofu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fa79c6944e3b85839981eb487b5ac2a5ce4c15f7cffb4bf8767ac9d43ed03393 - SHA-1:
11712db27ee950e56f7c06a36f3c5c6780974f1a - MD5:
5d5a4cb53c7eb1bb57b5d2c7ed8194cf - ssdeep:
768:0gGzpDVjpoAt+4iLGNQsu6ouU8flH3u+pdJVF57zN:BGFpjp2J6Xle+pdjF5fN - TLSH:
T1E6317CF340A7ED8C778EAB436DE61199A059D788A032D660459C772CD4BC6FE3F00A21 - Submitted as: borawixis-kegeluruxakij-jabofu.pdf
- File type: pdf · Size: 40706 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://dojulukasinu.weebly.com/uploads/1/3/0/7/130776790/pinizumajopew-jadifugizitijo-vimap-tobataporobe.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=essentials%20of%20abnormal%20psychology%206t, https://site-1038835.mozfiles.com/files/1038835/87043504389.pdf, https://site-1036917.mozfiles.com/files/1036917/79232391443.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=essentials%20of%20abnormal%20psychology%206t
- https://site-1038835.mozfiles.com/files/1038835/87043504389.pdf
- https://site-1036917.mozfiles.com/files/1036917/79232391443.pdf
- https://site-1044157.mozfiles.com/files/1044157/moxesawolo.pdf
- https://dojulukasinu.weebly.com/uploads/1/3/0/7/130776790/pinizumajopew-jadifugizitijo-vimap-tobataporobe.pdf
- https://wefolukozik.weebly.com/uploads/1/3/1/4/131406413/komabab.pdf
- https://site-1042666.mozfiles.com/files/1042666/31160884279.pdf
- https://site-1045415.mozfiles.com/files/1045415/28470746585.pdf
- https://site-1036767.mozfiles.com/files/1036767/81154883700.pdf
- https://site-1037860.mozfiles.com/files/1037860/fapukemurapap.pdf
- https://site-1038694.mozfiles.com/files/1038694/rerelimoburepix.pdf
- https://site-1043134.mozfiles.com/files/1043134/tijodojusulid.pdf
- https://site-1038511.mozfiles.com/files/1038511/dikutefexekipexaj.pdf
- https://site-1039688.mozfiles.com/files/1039688/95857311648.pdf
- https://site-1039492.mozfiles.com/files/1039492/lasio_keratin_treatment_instructions.pdf
- https://paguzijap.weebly.com/uploads/1/3/1/4/131453408/34bb4969e43.pdf
- https://zoveponezewuda.weebly.com/uploads/1/3/0/7/130738822/1865165.pdf
- https://xuvakaxatal.weebly.com/uploads/1/3/1/0/131070170/dawelusonevu-bodipalotit-xejemevunif.pdf
- https://cdn.shopify.com/s/files/1/0438/4597/6221/files/air_max_inverter_12000_btu_22_seer.pdf
- https://cdn.shopify.com/s/files/1/0498/1889/4491/files/dragon_priest_mask_skyrim_mod.pdf
- https://cdn.shopify.com/s/files/1/0437/8748/5342/files/affinities_of_protochordates.pdf
- https://cdn.shopify.com/s/files/1/0484/7370/2554/files/tixerusuw.pdf
- https://cdn.shopify.com/s/files/1/0486/2568/0542/files/anchors_aweigh_aa_key_west.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- site-1038835.mozfiles.com
- site-1036917.mozfiles.com
- site-1044157.mozfiles.com
- dojulukasinu.weebly.com
- wefolukozik.weebly.com
- site-1042666.mozfiles.com
- site-1045415.mozfiles.com
- site-1036767.mozfiles.com
- site-1037860.mozfiles.com
- site-1038694.mozfiles.com
- site-1043134.mozfiles.com
- site-1038511.mozfiles.com
- site-1039688.mozfiles.com
- site-1039492.mozfiles.com
- paguzijap.weebly.com
- zoveponezewuda.weebly.com
- xuvakaxatal.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report