MALICIOUS — jubabilobeki-tipelawoxovinaz-kavarasufosokoj-wofosekufeb.pdf
MALICIOUS — jubabilobeki-tipelawoxovinaz-kavarasufosokoj-wofosekufeb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
236f81eb2defefe9625795c66bcc834e92c0c20d4a6ec5f726ba1a16b8bb4465 - SHA-1:
0862369baacef66ffcfd76098eaaae40b81009b7 - MD5:
e82c2a9f127f4c8a897171eda659c834 - ssdeep:
768:yNgGzpD0pG6v6Mo1W7ItH4ZpweSB1Jb1kmF5tm0b0zHV7B/xEFWYljKhcEQlFlZ7:1GFgpG6OH0peB1km6B/xGJljK7EQIV4q - TLSH:
T1A532AEF31197CC5C7986AB93AEF728656189C38821339B6054CC7B6CD4B87BD7E00961 - Submitted as: jubabilobeki-tipelawoxovinaz-kavarasufosokoj-wofosekufeb.pdf
- File type: pdf · Size: 47430 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/vifotatilaw.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=big%20java%20early%20objects%205th%20edition%20s, https://uploads.strikinglycdn.com/files/4fda0f3e-162d-4f58-9d8a-bfbb15b89a8c/39647962293.pdf, https://uploads.strikinglycdn.com/files/b19ecf38-e415-4c81-b049-a18fd1a92571/dodekexujebazaviraxofarox.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=big%20java%20early%20objects%205th%20edition%20s
- https://uploads.strikinglycdn.com/files/4fda0f3e-162d-4f58-9d8a-bfbb15b89a8c/39647962293.pdf
- https://uploads.strikinglycdn.com/files/b19ecf38-e415-4c81-b049-a18fd1a92571/dodekexujebazaviraxofarox.pdf
- https://uploads.strikinglycdn.com/files/037c802b-2952-4a14-be46-a3e94374df26/bomiminawatavetasufuxebe.pdf
- https://uploads.strikinglycdn.com/files/4df0e9b8-1fd2-4e03-9b2c-d86f70e1bb45/joxumarun.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/vifotatilaw.pdf
- https://site-1042510.mozfiles.com/files/1042510/61188623993.pdf
- https://site-1039778.mozfiles.com/files/1039778/bitevumaj.pdf
- https://site-1048572.mozfiles.com/files/1048572/8193219850.pdf
- https://site-1037114.mozfiles.com/files/1037114/66940111730.pdf
- https://uploads.strikinglycdn.com/files/cffa4900-4e96-4774-836f-3905322bb23f/79446930665.pdf
- https://uploads.strikinglycdn.com/files/66e5beae-38fb-4822-8eb9-854d148ce5ac/32231953985.pdf
- https://uploads.strikinglycdn.com/files/7134fa3f-13fe-449f-a252-651fcb654e6e/33055357631.pdf
- https://uploads.strikinglycdn.com/files/ef744a3d-d8f2-48a7-875a-00ba58bf5dd3/66367781570.pdf
- https://mamexobupelo.weebly.com/uploads/1/3/1/3/131383482/2ea9bf5911bb1bb.pdf
- https://ganulexotugoris.weebly.com/uploads/1/3/1/1/131164012/9872142.pdf
- https://uploads.strikinglycdn.com/files/8d850122-2e41-4cb2-88c7-d7a67fb2897d/meveniful.pdf
- https://uploads.strikinglycdn.com/files/cf71bdc4-0b61-43b2-b7f8-33b94d365ee5/detafavobadipubemuja.pdf
- https://uploads.strikinglycdn.com/files/d9f5b4f4-88c8-45a5-84ea-67be201ecffc/55179986242.pdf
- https://uploads.strikinglycdn.com/files/6406bcc4-7ff9-42da-8cbd-63c7474036d7/21169159543.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- fijojonibiw.weebly.com
- site-1042510.mozfiles.com
- site-1039778.mozfiles.com
- site-1048572.mozfiles.com
- site-1037114.mozfiles.com
- mamexobupelo.weebly.com
- ganulexotugoris.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report