MALICIOUS — vajig-simubig-gevekawuzi-wemod.pdf
MALICIOUS — vajig-simubig-gevekawuzi-wemod.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
54f22aaa14be6372237a796fbb8e8769232681128418572b92675085536a0ead - SHA-1:
a74651f2d9d6b956fbcac1cec42abbe909a3613b - MD5:
79ec2fe46e7be4b889705649afc1cc29 - ssdeep:
1536:1GF2d4dk4B3h/bZNkcl40N9o4GWGQ+A/Sf:IF2d4Vh/bZNxl40Ne4YQ+AW - TLSH:
T14C35A0F311D3ED8D7B8F5B136DA62069604AD7886136A76088DC772CC4BC6ED7E01960 - Submitted as: vajig-simubig-gevekawuzi-wemod.pdf
- File type: pdf · Size: 58870 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/9653445.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=keiser%20m3%20bike%20manual, https://uploads.strikinglycdn.com/files/1cab5007-50e8-4069-ad25-fb32bd6a8ac9/spirited_away_piano_sheet_music_sixth_station.pdf, https://uploads.strikinglycdn.com/files/addd7f0e-ad08-4545-9589-0438e99ff7a5/gubulinefafidevizudegekex.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=keiser%20m3%20bike%20manual
- https://uploads.strikinglycdn.com/files/1cab5007-50e8-4069-ad25-fb32bd6a8ac9/spirited_away_piano_sheet_music_sixth_station.pdf
- https://uploads.strikinglycdn.com/files/addd7f0e-ad08-4545-9589-0438e99ff7a5/gubulinefafidevizudegekex.pdf
- https://cdn-cms.f-static.net/uploads/4379038/normal_5f93680cd2e29.pdf
- https://s3.amazonaws.com/jazofi/9577983725.pdf
- https://uploads.strikinglycdn.com/files/ba9138e0-3fbf-41f9-8fbf-15b03c70bbb9/vapaxufe.pdf
- https://s3.amazonaws.com/taturi/jspdf_autotable_multiple_tables_example.pdf
- https://uploads.strikinglycdn.com/files/7ba00196-13e0-4ecd-848a-d2c02c248dd2/bible_study_guide_download.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/9653445.pdf
- https://s3.amazonaws.com/susopuzupure/37208281241.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/nipomomuka_gisotufeje.pdf
- https://lotagixowila.weebly.com/uploads/1/3/1/1/131164100/kasovekof.pdf
- https://digulowewuw.weebly.com/uploads/1/3/4/3/134363346/7059294.pdf
- https://uploads.strikinglycdn.com/files/5fe1c856-fa0f-46a5-b9b3-cba2cfb02556/6793791373.pdf
- https://uploads.strikinglycdn.com/files/e4f9fe22-4041-4800-9606-edaeae055f0f/scaner1c.dll__1_8.3.pdf
- https://genamimiwovem.weebly.com/uploads/1/3/1/6/131636881/jejodu.pdf
- https://telexetobowu.weebly.com/uploads/1/3/4/3/134339901/7530349.pdf
- https://uploads.strikinglycdn.com/files/8437fd34-706c-4c95-9f30-f350fb029f9c/atomic_numbers_and_atomic_mass_worksheet_answers.pdf
- https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/70a072.pdf
- https://uploads.strikinglycdn.com/files/8bd9a583-c092-4f08-b80e-7c359756008f/8120695241.pdf
- https://damijuvik.weebly.com/uploads/1/3/1/3/131381376/padizosoti.pdf
- https://cdn-cms.f-static.net/uploads/4379982/normal_5f8c62c5528d8.pdf
- https://uploads.strikinglycdn.com/files/319b95bf-2878-4bd0-aefd-370d442733e4/cancion_de_hielo_y_fuego_gratis.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- vuxozajuje.weebly.com
- jakedekokobara.weebly.com
- lotagixowila.weebly.com
- digulowewuw.weebly.com
- genamimiwovem.weebly.com
- telexetobowu.weebly.com
- walijogopabo.weebly.com
- damijuvik.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report