MALICIOUS — jedegevoxiniriwi.pdf
MALICIOUS — jedegevoxiniriwi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (77/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2604e1f750fca902b7a0a37d78f0839d7204ae7f2839df6d1bd746ef7288f5c3 - SHA-1:
cf5afa61b1de6ecc63c83ffe9f6e2e8237e06685 - MD5:
da07d5e7b11cfb0be0f0ceb3f58a4382 - ssdeep:
1536:FGFvp8VYkRoIH5RBaNpkBud+xejXMUfajJ:YFvp8V4trd+xTuG - TLSH:
T1B2338DF310D3EC8CBA8B6B076CB7149AA04DD3886236D79061DC762DD47C6BD6E215A0 - Submitted as: jedegevoxiniriwi.pdf
- File type: pdf · Size: 49769 bytes
- Verdict: malicious (77/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 77/100 is the fusion of 5 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/01bde2e6-df3b-4584-a0cb-1cef3228fe67/31673191744.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=shrink%20pdf%20file, https://uploads.strikinglycdn.com/files/01bde2e6-df3b-4584-a0cb-1cef3228fe67/31673191744.pdf, https://uploads.strikinglycdn.com/files/da1f5b92-6739-4f41-a1b9-a65d4e558c01/pefizatunabanivupogunosi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=shrink%20pdf%20file
- https://uploads.strikinglycdn.com/files/01bde2e6-df3b-4584-a0cb-1cef3228fe67/31673191744.pdf
- https://uploads.strikinglycdn.com/files/da1f5b92-6739-4f41-a1b9-a65d4e558c01/pefizatunabanivupogunosi.pdf
- https://uploads.strikinglycdn.com/files/703d4e1b-3602-4305-a05f-200ea5de9224/jifibexifemolitak.pdf
- https://uploads.strikinglycdn.com/files/18cfee70-636d-49da-9ef4-e677c170e299/pozisufuzo.pdf
- https://wemibevufiwoseb.weebly.com/uploads/1/3/0/8/130813314/b199df.pdf
- https://pafuwaron.weebly.com/uploads/1/3/4/3/134385690/jomofilek_navit.pdf
- https://kelipibefis.weebly.com/uploads/1/3/4/5/134500531/xikarow.pdf
- https://fogajabewe.weebly.com/uploads/1/3/4/1/134131707/f1f5c298c.pdf
- https://gejatovuri.weebly.com/uploads/1/3/1/4/131406669/mibuwazugaxiwom-zapupawuve-fonusixodo.pdf
- https://cdn.shopify.com/s/files/1/0505/0518/7512/files/hoover_steamvac_portable_deep_cleaner_manual.pdf
- https://cdn.shopify.com/s/files/1/0431/3730/2685/files/tecumseh_engine_maintenance_manual.pdf
- https://cdn.shopify.com/s/files/1/0501/8084/9852/files/gixukudup.pdf
- https://cdn.shopify.com/s/files/1/0486/2469/7509/files/scribblenauts_unlimited_apk_no_obb.pdf
- https://cdn.shopify.com/s/files/1/0432/0319/9138/files/40234285809.pdf
- https://uploads.strikinglycdn.com/files/8df89d64-b163-4ad0-aba1-6e53f1b3d6ee/2771017464.pdf
- https://uploads.strikinglycdn.com/files/4a252bd3-4e6e-484e-b6fc-691667fe3bd3/gukogovaveke.pdf
- https://uploads.strikinglycdn.com/files/0c4c5579-5ea2-4dc9-9114-853a092d3e4f/.pdf
- https://uploads.strikinglycdn.com/files/72e35636-f176-4264-9890-da9dcf246f51/tewilufuvepetadubagivos.pdf
- https://uploads.strikinglycdn.com/files/bb979515-574e-4fe2-a245-a75b67bfc796/10135328309.pdf
- https://s3.amazonaws.com/jifesu/lebojarawirogixa.pdf
- https://s3.amazonaws.com/duzexefemosaxe/mapa_de_carreteras_del_estado_de_mexico.pdf
- https://uploads.strikinglycdn.com/files/bb0e4080-9b1f-4732-9397-40bcc4f00a8a/boxafat.pdf
- https://uploads.strikinglycdn.com/files/e59d7ccd-87fc-4c14-82ef-19e3e3a4c614/fikemugezaxezanukif.pdf
- https://uploads.strikinglycdn.com/files/6f93f722-763d-4431-80e9-147e16202263/intel_82801_pci_bridge_244e_windows.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- wemibevufiwoseb.weebly.com
- pafuwaron.weebly.com
- kelipibefis.weebly.com
- fogajabewe.weebly.com
- gejatovuri.weebly.com
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report