MALICIOUS — mazijalokazamipime.pdf
MALICIOUS — mazijalokazamipime.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
af5747154618352478f782b441534bdb6478580a20bd6839999f96b749ead039 - SHA-1:
061a98babaa7f2abb40719b7ed5f2485e14f5561 - MD5:
2008e404346d16f3f8ef7db518662386 - ssdeep:
768:TgGzpDrphq5vigsQUZ1xONqdKDTkbdvvr9hG5ehvoqQI0j0sve:sGFnph4KUTedre5ehvoXjTve - TLSH:
T191327CF35497DD8D7E8B8B83ADEB255A5189C388B226D710488C762CD4BC5BCBF10950 - Submitted as: mazijalokazamipime.pdf
- File type: pdf · Size: 44240 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/038885c85ecf8f0.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=la%20maldicion%20de%20hill%20house%20libro, https://jivexine.weebly.com/uploads/1/3/1/3/131380908/vokuzamik.pdf, https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/038885c85ecf8f0.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=la%20maldicion%20de%20hill%20house%20libro
- https://jivexine.weebly.com/uploads/1/3/1/3/131380908/vokuzamik.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/038885c85ecf8f0.pdf
- https://fuparududewon.weebly.com/uploads/1/3/1/8/131856041/7600545.pdf
- https://takijotirodone.weebly.com/uploads/1/3/1/6/131637658/gejodixapamuf.pdf
- https://cdn.shopify.com/s/files/1/0483/0137/5650/files/led_flashlight_with_precision_screwdrivers.pdf
- https://cdn.shopify.com/s/files/1/0482/9636/2148/files/29850415986.pdf
- https://cdn.shopify.com/s/files/1/0433/8538/9212/files/gladiator_heroes_mod_apk_3.2.4.pdf
- https://cdn.shopify.com/s/files/1/0430/8579/1383/files/pujivirisiveso.pdf
- https://cdn.shopify.com/s/files/1/0458/9620/4442/files/99368103883.pdf
- https://uploads.strikinglycdn.com/files/2720af06-3d59-4c2e-9b7d-a83e7823d804/rokiwunepaxizelepivatak.pdf
- https://uploads.strikinglycdn.com/files/1b50681b-4117-43b2-8fc4-723d1bc6f86e/gojetigideginoro.pdf
- https://site-1037121.mozfiles.com/files/1037121/74194804713.pdf
- https://site-1039999.mozfiles.com/files/1039999/nojofajuwanozegekigolebe.pdf
- https://site-1043438.mozfiles.com/files/1043438/58727665613.pdf
- https://uploads.strikinglycdn.com/files/fb9fc500-c43b-4eb3-b496-cf7150c22ad6/22261049391.pdf
- https://uploads.strikinglycdn.com/files/8649ad14-cdba-469e-b821-7fd99d50a469/rijekigovebozikejogadi.pdf
- https://uploads.strikinglycdn.com/files/b6011346-ec27-4fa0-9224-7412a6ff216c/21592471469.pdf
- https://uploads.strikinglycdn.com/files/0bc55a7c-e44d-4484-8db4-69d62814958d/deneparigega.pdf
- https://uploads.strikinglycdn.com/files/6c54de22-343a-4de3-a856-2a968b684a16/16680455719.pdf
- https://cdn.shopify.com/s/files/1/0496/1258/7171/files/limiting_and_excess_reactants.pdf
- https://cdn.shopify.com/s/files/1/0479/7828/3164/files/camp_hill_meals_on_wheels.pdf
- https://cdn.shopify.com/s/files/1/0482/9387/1778/files/18089745253.pdf
- https://cdn.shopify.com/s/files/1/0499/0415/6830/files/vocabulary_workshop_level_f_unit_4_answers_choosing_the_right_word.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- jivexine.weebly.com
- mojivimimujovo.weebly.com
- fuparududewon.weebly.com
- takijotirodone.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1037121.mozfiles.com
- site-1039999.mozfiles.com
- site-1043438.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report