MALICIOUS — vuxuwanu-giwosofib-begemekofegesu.pdf
MALICIOUS — vuxuwanu-giwosofib-begemekofegesu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 1 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
436a5871ba803463087a81e263a279cb2a6d961374daecac5edfb55923690f9e - SHA-1:
7d70ad1239cc226125975ac03598994db5064be2 - MD5:
558f16caeacac6585d790eba5878c1be - ssdeep:
768:0gGzpDGpHduTXK3DaALQznW78uwWNl6JCDKMYJtfo3ipZG:BGFCpH+WJNlmCWMYfqipZG - TLSH:
T1A7304AF31093ED8C7A8FAB43ADEB155D508AC7886037E7A04498672DD4BC9ED7E00961 - Submitted as: vuxuwanu-giwosofib-begemekofegesu.pdf
- File type: pdf · Size: 37305 bytes
- Verdict: malicious (71/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/sujikuw.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=qwixx%20score%20sheets%20pdf, https://uploads.strikinglycdn.com/files/14e2e6ec-e3f8-488a-8964-aed1e4d8b9ef/33149038689.pdf, https://uploads.strikinglycdn.com/files/232e2be7-d841-4900-9ebd-27cc0ee5c1a4/10787629702.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=qwixx%20score%20sheets%20pdf
- https://uploads.strikinglycdn.com/files/14e2e6ec-e3f8-488a-8964-aed1e4d8b9ef/33149038689.pdf
- https://uploads.strikinglycdn.com/files/232e2be7-d841-4900-9ebd-27cc0ee5c1a4/10787629702.pdf
- https://uploads.strikinglycdn.com/files/3bdb967b-61f0-4667-90fe-f514ead86c09/17672559197.pdf
- https://uploads.strikinglycdn.com/files/ea274dd0-ac32-4311-ba95-e431f032c5a7/faboxexuxusosonize.pdf
- https://uploads.strikinglycdn.com/files/88022a6f-ee2b-48d3-84a2-e127207cf971/43190242213.pdf
- https://cdn.shopify.com/s/files/1/0465/0077/4046/files/veggietales_jonah_sing_along_songs_and_more_credits.pdf
- https://cdn.shopify.com/s/files/1/0266/8498/1436/files/coat_rack_shelf_target.pdf
- https://cdn.shopify.com/s/files/1/0459/3277/3543/files/bomawonuzutofezatizupaje.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/sujikuw.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/tunitulo.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/1867598.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/1346883.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/tidivobinimigip-banez-batipafon.pdf
- https://site-1042198.mozfiles.com/files/1042198/vibamavi.pdf
- https://site-1039903.mozfiles.com/files/1039903/bakaborenonazumobe.pdf
- https://site-1039669.mozfiles.com/files/1039669/60855567391.pdf
- https://site-1043559.mozfiles.com/files/1043559/dunexane.pdf
- https://site-1037218.mozfiles.com/files/1037218/71254534204.pdf
- https://cdn.shopify.com/s/files/1/0481/8518/0327/files/happy_new_year_banner_design.pdf
- https://cdn.shopify.com/s/files/1/0440/5529/8213/files/sudizoga.pdf
- https://cdn.shopify.com/s/files/1/0496/8172/7640/files/cereal_avena_quaker_engorda.pdf
- https://cdn.shopify.com/s/files/1/0434/0655/7340/files/fifa_17_mobile_apk_indir.pdf
- https://cdn.shopify.com/s/files/1/0434/7848/3097/files/vujetugubowiri.pdf
- https://uploads.strikinglycdn.com/files/83adb266-23cb-43e7-bb1b-cf0fc00c4213/zewasite.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- mojivimimujovo.weebly.com
- dutitujazekap.weebly.com
- vuxozajuje.weebly.com
- boguvetasitob.weebly.com
- zoxuzuxebexot.weebly.com
- site-1042198.mozfiles.com
- site-1039903.mozfiles.com
- site-1039669.mozfiles.com
- site-1043559.mozfiles.com
- site-1037218.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report