MALICIOUS — sisudaganoloninizanolen.pdf
MALICIOUS — sisudaganoloninizanolen.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a4bf9c8b7809ae2b8224d8a2cd7c960891a2e573f25a890180bfaa02ea6283dd - SHA-1:
d14418723c2abd8f30f9229c4327228e5ebb0257 - MD5:
f2c4b84c0b170b80a99d5ace865fdc24 - ssdeep:
768:AgGzpDep62+NGYbw0lKHW1dWa7fgoO30ZWWGU52FVYx7xzGTnKL4Osc:NGFap8wW1EKgX08WvoK7xzB4Osc - TLSH:
T15D315DF351E7ED8C7A8E5B07BDB61159A48AC7CD603697604488372CC0BCAFE6E01961 - Submitted as: sisudaganoloninizanolen.pdf
- File type: pdf · Size: 40071 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/3250b5961ed1.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=facebook+old+version+free+download+apk, https://site-1043123.mozfiles.com/files/1043123/65695649908.pdf, https://site-1042539.mozfiles.com/files/1042539/history_of_apparel_industry.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=facebook+old+version+free+download+apk
- https://site-1043123.mozfiles.com/files/1043123/65695649908.pdf
- https://site-1042539.mozfiles.com/files/1042539/history_of_apparel_industry.pdf
- https://site-1037881.mozfiles.com/files/1037881/71251950910.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/3250b5961ed1.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/velukuziralijomem.pdf
- https://zevigetadafuwun.weebly.com/uploads/1/3/0/9/130969942/46342becd04fce3.pdf
- https://legadiduzavof.weebly.com/uploads/1/3/2/6/132681829/tajopekora.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f870af12352c.pdf
- https://cdn-cms.f-static.net/uploads/4369323/normal_5f88bb2c9763e.pdf
- https://cdn-cms.f-static.net/uploads/4372737/normal_5f88bb49b0d81.pdf
- https://cdn-cms.f-static.net/uploads/4366063/normal_5f87330b4c636.pdf
- https://cdn-cms.f-static.net/uploads/4368991/normal_5f87e9f5b18f1.pdf
- https://uploads.strikinglycdn.com/files/ad33a90b-5bee-4eb2-836e-54f0923a93b6/finaputepi.pdf
- https://uploads.strikinglycdn.com/files/21c95e67-3814-4ffd-895d-df0ed974aa3b/52008669055.pdf
- https://uploads.strikinglycdn.com/files/07958585-0a57-4eae-9576-7662b905aeba/bavemazawofojeraduxe.pdf
- https://uploads.strikinglycdn.com/files/e7ed0f43-22de-452d-a2a4-6912e088d241/basuleno.pdf
- https://fizolapojola.weebly.com/uploads/1/3/1/3/131383549/gogekag.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/aa94aa7f99c.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/b4b3eb38b.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/kopiwu_gotatumeturi_bovejixegas_vivikow.pdf
- https://site-1040248.mozfiles.com/files/1040248/9589558041.pdf
- https://site-1036874.mozfiles.com/files/1036874/temobodidolebosetelov.pdf
- https://site-1039711.mozfiles.com/files/1039711/fepadixopofowoxabopi.pdf
- https://site-1039610.mozfiles.com/files/1039610/66682990034.pdf
Embedded domains
- ggtraff.ru
- site-1043123.mozfiles.com
- site-1042539.mozfiles.com
- site-1037881.mozfiles.com
- mojivimimujovo.weebly.com
- juragubiv.weebly.com
- zevigetadafuwun.weebly.com
- legadiduzavof.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- fizolapojola.weebly.com
- gimejexoxixaza.weebly.com
- keniwuki.weebly.com
- site-1040248.mozfiles.com
- site-1036874.mozfiles.com
- site-1039711.mozfiles.com
- site-1039610.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report