MALICIOUS — lemavetobowogis_vexakopasejo_sositefafum.pdf
MALICIOUS — lemavetobowogis_vexakopasejo_sositefafum.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fe2d801d582be323f504dd2ef34603ad083b978e310213bf45c1c4008fb1280c - SHA-1:
de7ef020cc773659b5187cf92ef427e40f2f32e2 - MD5:
edc50c96a2e1fb56cc128bf53654d604 - ssdeep:
1536:yGFspOlPWq+brlbU8NSL8IvY4W+emKNP:rFspOlPOJbbNoZQl8K5 - TLSH:
T105339DF710A7ED4CBA8A2747ADE715E56289C3887237A750498C7B2CC0B85BC7F10861 - Submitted as: lemavetobowogis_vexakopasejo_sositefafum.pdf
- File type: pdf · Size: 50413 bytes
- Verdict: malicious (75/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/tevow.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=zohar%20pdf%20portugues%20download, https://uploads.strikinglycdn.com/files/efcbf066-533d-45ad-89a1-8cc0800eb141/74362878916.pdf, https://uploads.strikinglycdn.com/files/9b290d90-a43a-4317-afdb-11aa920998c5/wogola.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=zohar%20pdf%20portugues%20download
- https://uploads.strikinglycdn.com/files/efcbf066-533d-45ad-89a1-8cc0800eb141/74362878916.pdf
- https://uploads.strikinglycdn.com/files/9b290d90-a43a-4317-afdb-11aa920998c5/wogola.pdf
- https://uploads.strikinglycdn.com/files/04988470-c793-4ddf-8025-7138b7bddcfd/18183128755.pdf
- https://uploads.strikinglycdn.com/files/1b122aec-53e4-4bc2-aa49-712bd4c998cc/45363828987.pdf
- https://site-1043120.mozfiles.com/files/1043120/rewowopifibugu.pdf
- https://site-1038531.mozfiles.com/files/1038531/17391124639.pdf
- https://site-1038779.mozfiles.com/files/1038779/kulitagiwuxolofewitun.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/tevow.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/8a68c5dc19.pdf
- https://cdn-cms.f-static.net/uploads/4367278/normal_5f87ad8b9b568.pdf
- https://cdn-cms.f-static.net/uploads/4369166/normal_5f87aae7a4b7a.pdf
- https://cdn-cms.f-static.net/uploads/4365580/normal_5f875ce766748.pdf
- https://cdn-cms.f-static.net/uploads/4365567/normal_5f871604b1133.pdf
- https://cdn-cms.f-static.net/uploads/4365634/normal_5f8763a3a9df3.pdf
- https://uploads.strikinglycdn.com/files/e2ddafab-d406-4228-b613-92111519f368/17808982444.pdf
- https://uploads.strikinglycdn.com/files/9c6d31f4-6616-44a5-bf38-5b9b28a0bad7/7548334374.pdf
- https://uploads.strikinglycdn.com/files/e2a5d5b2-dcfa-4dfa-97e6-3b662b42e62b/potenabo.pdf
- https://uploads.strikinglycdn.com/files/fdb24390-ec64-4163-8a99-3215ed995cc2/gitoze.pdf
- https://uploads.strikinglycdn.com/files/6a086a8b-8498-44b2-932e-9118b381b476/bevebotewopakuwapip.pdf
- https://uploads.strikinglycdn.com/files/65d12ce0-f638-4e5e-91bc-a9f8dabfe11c/80023222538.pdf
- https://uploads.strikinglycdn.com/files/5b42fff3-c898-4cf0-bb2e-2b74f8e71fc9/41245388671.pdf
- https://uploads.strikinglycdn.com/files/d60282a6-0ed2-49b5-a71f-69f4c6ef35cc/74092963600.pdf
- https://uploads.strikinglycdn.com/files/4753bb95-4788-4d72-b1c8-cfa573f181db/gozasofer.pdf
- https://uploads.strikinglycdn.com/files/f944f3a1-0264-494c-bde8-bf5996949e2a/kibad.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1043120.mozfiles.com
- site-1038531.mozfiles.com
- site-1038779.mozfiles.com
- jaserasozupog.weebly.com
- boguvetasitob.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report