MALICIOUS — tosafuwovama.pdf
MALICIOUS — tosafuwovama.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
84666eba614b37e73260df4187e0f32730c5c6e0ef13609dbb7f8ccafb49353b - SHA-1:
25790419d93c0f822e44406aa13a6d19457d61e2 - MD5:
473f3bd58fcb9a55cb23f6c9a0045b7f - ssdeep:
1536:9GFherEgWpnRPRwjNPsWGoo+0WhE1QgSTxt:AFheIgWIOoo+FE1QR3 - TLSH:
T10B33AEF360A3EC8C77CAAF13B96715585247CB4C31368AA444997B3CC478ABE7D10661 - Submitted as: tosafuwovama.pdf
- File type: pdf · Size: 51549 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jizonuwuko.weebly.com/uploads/1/3/0/8/130814311/wedit_bajojabo.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=mystic%20timbers%20kings%20island, https://jizonuwuko.weebly.com/uploads/1/3/0/8/130814311/wedit_bajojabo.pdf, https://xavoxoxuda.weebly.com/uploads/1/3/1/3/131379246/1da7ccef7.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: additional-actions, uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=mystic%20timbers%20kings%20island
- https://jizonuwuko.weebly.com/uploads/1/3/0/8/130814311/wedit_bajojabo.pdf
- https://xavoxoxuda.weebly.com/uploads/1/3/1/3/131379246/1da7ccef7.pdf
- https://xadaxiwunitari.weebly.com/uploads/1/3/0/8/130814235/88fd3e4d1.pdf
- https://cdn-cms.f-static.net/uploads/4393208/normal_5f8f20fbec2df.pdf
- https://cdn-cms.f-static.net/uploads/4366405/normal_5f897557f205b.pdf
- https://cdn-cms.f-static.net/uploads/4369788/normal_5f89b711c17eb.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/bekalan.pdf
- https://zigegawemofeza.weebly.com/uploads/1/3/1/4/131406932/vuzolek.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/fibaxizimudez.pdf
- https://lagukekejase.weebly.com/uploads/1/3/0/8/130815031/wufebefazitogaxubobi.pdf
- https://s3.amazonaws.com/kavitokolezub/98507179505.pdf
- https://s3.amazonaws.com/pazifetanegapu/vapufotodalikotetodakaf.pdf
- https://s3.amazonaws.com/susopuzupure/anesthesia_case_files.pdf
- https://s3.amazonaws.com/gupuso/cbse_12th_accountancy_book.pdf
- https://uploads.strikinglycdn.com/files/d9aee5a3-cf1c-4dae-99c9-3e2c79c14d2e/43816589994.pdf
- https://uploads.strikinglycdn.com/files/45d2c315-549b-42fe-9f11-d3262ed66bfc/zegagomirabonumixu.pdf
- https://uploads.strikinglycdn.com/files/dc7bc889-efd4-471d-98a3-86e0776ef101/90806832086.pdf
- https://uploads.strikinglycdn.com/files/82bb2233-1b7a-45f4-aa1c-2038f482d16b/26689352963.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- jizonuwuko.weebly.com
- xavoxoxuda.weebly.com
- xadaxiwunitari.weebly.com
- cdn-cms.f-static.net
- genigudepa.weebly.com
- zigegawemofeza.weebly.com
- jakedekokobara.weebly.com
- lagukekejase.weebly.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report