MALICIOUS — fijides.pdf
MALICIOUS — fijides.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
17cd3fd44b901621339150359ca4df4674a7830494d4e27bb855ea7ed79a27a7 - SHA-1:
1b6052e3c1436b84b0990996caf44bb6c02ad012 - MD5:
e1baa4302795df5b43ca62ad1b2654f5 - ssdeep:
768:SgGzpDtpcsvkGdk+HBexJ9WTGbj8owPJ19vhF8mdJV/5RJgN5Y2j37tCaRJ7CPjG:PGF5pqP70J19vhF8m5BRJ85jdRCPjwMe - TLSH:
T1D633AEF351DBEE4C7E8A9B0B5DE61259618AC38C6236E75055CCB72CC47CABC6E10860 - Submitted as: fijides.pdf
- File type: pdf · Size: 49102 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/7d7b6617ab8.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=free%20business%20model%20canvas%20editable%20pdf, https://cdn-cms.f-static.net/uploads/4371814/normal_5f886e22b01bc.pdf, https://cdn-cms.f-static.net/uploads/4368227/normal_5f8bd8ce4b934.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=free%20business%20model%20canvas%20editable%20pdf
- https://cdn-cms.f-static.net/uploads/4371814/normal_5f886e22b01bc.pdf
- https://cdn-cms.f-static.net/uploads/4368227/normal_5f8bd8ce4b934.pdf
- https://cdn-cms.f-static.net/uploads/4380230/normal_5f8ba16eaa568.pdf
- https://cdn-cms.f-static.net/uploads/4366022/normal_5f87198a452ae.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/7d7b6617ab8.pdf
- https://pituluwo.weebly.com/uploads/1/3/1/4/131437949/0aec8c20a.pdf
- https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/xodimopulepibu-xagizemudi-bofin.pdf
- https://cdn.shopify.com/s/files/1/0429/9735/0554/files/58686714763.pdf
- https://cdn.shopify.com/s/files/1/0462/3669/6725/files/51752971437.pdf
- https://cdn.shopify.com/s/files/1/0492/0649/3350/files/mupeguj.pdf
- https://cdn.shopify.com/s/files/1/0268/7513/4135/files/79012877175.pdf
- https://cdn.shopify.com/s/files/1/0494/3685/2391/files/jupewunete.pdf
- https://cdn.shopify.com/s/files/1/0434/3870/2748/files/39970883556.pdf
- https://uploads.strikinglycdn.com/files/607f1b95-19e9-4fa6-a0eb-a17005cdd112/31262414966.pdf
- https://uploads.strikinglycdn.com/files/95b54d9b-399f-4691-85b2-e56b51552e3e/rekubigizus.pdf
- https://uploads.strikinglycdn.com/files/30402821-9e52-496f-9267-b85158a5bd65/nakomapezedifokopisogiwer.pdf
- https://uploads.strikinglycdn.com/files/f5c81466-f57b-4a6d-ac26-a37d03a800c1/vegasejakepimosotu.pdf
- https://cdn.shopify.com/s/files/1/0434/4948/3426/files/gujulenomudotenux.pdf
- https://cdn.shopify.com/s/files/1/0500/2415/3248/files/50038513412.pdf
- https://cdn.shopify.com/s/files/1/0503/8745/2078/files/janumet_patient_assistance_form.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- vuxozajuje.weebly.com
- pituluwo.weebly.com
- dirigesibujov.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report