MALICIOUS — kijewo-fugogugi.pdf
MALICIOUS — kijewo-fugogugi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
79f8397f7ffd3dd832eea5e70ea90afaa480bdfa15d67cc5f17b83fb476c60c2 - SHA-1:
baef9fcca60bed307569142d71d5d66b6662985a - MD5:
178c8e56eab2bc2c6139089e26995a9b - ssdeep:
1536:AGFPp4MtaRttl4p6ycfpjlWfLLqZ0+L02:NFPpjtUm67pjUaxR - TLSH:
T1FB34AEF314A7DD8CBA87D783ACA710A26046D38972339AA04588773DC4BC2BD7F10961 - Submitted as: kijewo-fugogugi.pdf
- File type: pdf · Size: 56723 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://ridolagu.weebly.com/uploads/1/3/0/7/130775195/gipijepaborakon.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=arm%20template%20for%20azure%20app%20service, https://ridolagu.weebly.com/uploads/1/3/0/7/130775195/gipijepaborakon.pdf, https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/zanadutut_wexudafenatogun_jetomefoja.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=arm%20template%20for%20azure%20app%20service
- https://ridolagu.weebly.com/uploads/1/3/0/7/130775195/gipijepaborakon.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/zanadutut_wexudafenatogun_jetomefoja.pdf
- https://kelobutino.weebly.com/uploads/1/3/0/9/130969458/noletubupawozix.pdf
- https://nobinetezo.weebly.com/uploads/1/3/0/9/130969761/646693.pdf
- https://xebikazogede.weebly.com/uploads/1/3/2/7/132740990/28fef585a7.pdf
- https://site-1042554.mozfiles.com/files/1042554/48451981794.pdf
- https://uploads.strikinglycdn.com/files/c9e15ed5-df2f-4913-b3bb-3cde23466d2b/xunomumawuludigutegake.pdf
- https://uploads.strikinglycdn.com/files/79823eda-5233-420a-b945-b631cb661f67/bifakisivipuza.pdf
- https://uploads.strikinglycdn.com/files/e956c567-6766-4bfe-8151-48a3789e0d34/93529445088.pdf
- https://uploads.strikinglycdn.com/files/df7815e2-4233-40ac-8919-9e6ed8ceaaee/71714061310.pdf
- https://site-1038650.mozfiles.com/files/1038650/40782103580.pdf
- https://site-1044204.mozfiles.com/files/1044204/29906520226.pdf
- https://site-1036826.mozfiles.com/files/1036826/sixuzukaxifaviso.pdf
- https://site-1036850.mozfiles.com/files/1036850/82908860015.pdf
- https://site-1043438.mozfiles.com/files/1043438/gumerud.pdf
- https://cdn-cms.f-static.net/uploads/4366627/normal_5f8784696f1cb.pdf
- https://cdn-cms.f-static.net/uploads/4366400/normal_5f87790f8dbf8.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f8743b74619b.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/2593159.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/038885c85ecf8f0.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/duwivif.pdf
- https://mijisurux.weebly.com/uploads/1/3/1/0/131070147/zudivomebavef_mejomu_keludutik_gexino.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- ridolagu.weebly.com
- jakedekokobara.weebly.com
- kelobutino.weebly.com
- nobinetezo.weebly.com
- xebikazogede.weebly.com
- site-1042554.mozfiles.com
- uploads.strikinglycdn.com
- site-1038650.mozfiles.com
- site-1044204.mozfiles.com
- site-1036826.mozfiles.com
- site-1036850.mozfiles.com
- site-1043438.mozfiles.com
- cdn-cms.f-static.net
- guwomenod.weebly.com
- mojivimimujovo.weebly.com
- genigudepa.weebly.com
- mijisurux.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report