MALICIOUS — vajowonowikalow.pdf
MALICIOUS — vajowonowikalow.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 1 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2759c83f2d66d78c9aa49242cba04dd5260041f7fc037434b9b4810ba83d7743 - SHA-1:
6c6f1d02f30c6430b3691f16f185246a17109a10 - MD5:
fca00e24b56b836da69e781ae480dff7 - ssdeep:
384:psFlS3K6XgKV7cAgdOpW+0lpKD2jKZkSqb/skt4dYfc7yxJSiCclvW4nrpq1J2Sc:9gGzpDmpKSD1sjOx+Co1J2ycmpVsH - TLSH:
T1A12F7CF740A7ED8C3AC7AB936DAB15992049C3886226A75046DC7A2CC4FC6BD7F00D51 - Submitted as: vajowonowikalow.pdf
- File type: pdf · Size: 34225 bytes
- Verdict: malicious (71/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://pasugewu.weebly.com/uploads/1/3/1/0/131071180/fuxegosimipu.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=ver%20crep%C3%BAsculo%20online%20espa%C3%B1ol, https://sanuvexugivi.weebly.com/uploads/1/3/1/6/131606490/lolitu_fapepaxoxog.pdf, https://vebifejelib.weebly.com/uploads/1/3/0/7/130775119/7c85ff5f2.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=ver%20crep%C3%BAsculo%20online%20espa%C3%B1ol
- https://sanuvexugivi.weebly.com/uploads/1/3/1/6/131606490/lolitu_fapepaxoxog.pdf
- https://vebifejelib.weebly.com/uploads/1/3/0/7/130775119/7c85ff5f2.pdf
- https://wipomozexabezi.weebly.com/uploads/1/3/0/7/130776841/zomedan.pdf
- https://tumixivig.weebly.com/uploads/1/3/1/6/131636813/lejofutuz.pdf
- https://cdn.shopify.com/s/files/1/0496/5738/1015/files/fexuruzakunesiguwi.pdf
- https://uploads.strikinglycdn.com/files/3447864a-dd5f-457b-8e40-b534c23e4ee8/zisaxawiv.pdf
- https://uploads.strikinglycdn.com/files/9d9c4be4-fb2d-4fbf-b5ff-5e7896e86c16/61351117114.pdf
- https://uploads.strikinglycdn.com/files/eabd69cd-99be-4754-9997-022061f01d07/kazevaxifewofitonotivotox.pdf
- https://pasugewu.weebly.com/uploads/1/3/1/0/131071180/fuxegosimipu.pdf
- https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/6583597.pdf
- https://fakimodixoto.weebly.com/uploads/1/3/0/7/130739088/zadofurijokub.pdf
- https://xadaxiwunitari.weebly.com/uploads/1/3/0/8/130814235/zuvigajudu_dunifitikato.pdf
- https://uploads.strikinglycdn.com/files/7581934f-d7b7-4099-b711-f44e29806948/91752131536.pdf
- https://uploads.strikinglycdn.com/files/e22757e1-5be8-4f54-ada2-4b144e69f094/72142369748.pdf
- https://uploads.strikinglycdn.com/files/820161ae-da34-4bff-8007-0d43ea42f4f0/jezobajij.pdf
- https://cdn-cms.f-static.net/uploads/4366620/normal_5f8b2cb192c6e.pdf
- https://cdn-cms.f-static.net/uploads/4374522/normal_5f8b9da0b3d06.pdf
- https://cdn-cms.f-static.net/uploads/4369905/normal_5f882d65be706.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- sanuvexugivi.weebly.com
- vebifejelib.weebly.com
- wipomozexabezi.weebly.com
- tumixivig.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- pasugewu.weebly.com
- dirigesibujov.weebly.com
- fakimodixoto.weebly.com
- xadaxiwunitari.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report