MALICIOUS — jefifuxewa.pdf
MALICIOUS — jefifuxewa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b774046a02957a1e7020677dac9361d8e7d6e33f88b9c0ef68ad657a2a6e9e65 - SHA-1:
7b7478cce4fc00f71d4654f4318f7a4a8f9d669f - MD5:
4ddfa24d425b688142e8d3903c1b4670 - ssdeep:
768:7VgGzpDfjpoTHzwiFIIJpe+aU30cZaoH:KGFfpl3Se+aZcTH - TLSH:
T118306CF340A3DC8C7A8F6F035EAB1059918AD38DA123D2A059D8762DD47C6FD7E00961 - Submitted as: jefifuxewa.pdf
- File type: pdf · Size: 35894 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/duwivif.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=environ%20automotive%20chelmsford, https://site-1048226.mozfiles.com/files/1048226/24219146693.pdf, https://site-1040388.mozfiles.com/files/1040388/lowugezeboligulejikasamo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=environ%20automotive%20chelmsford
- https://site-1048226.mozfiles.com/files/1048226/24219146693.pdf
- https://site-1040388.mozfiles.com/files/1040388/lowugezeboligulejikasamo.pdf
- https://site-1036977.mozfiles.com/files/1036977/48906056750.pdf
- https://site-1040321.mozfiles.com/files/1040321/28418816662.pdf
- https://site-1040432.mozfiles.com/files/1040432/50019464535.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/duwivif.pdf
- https://site-1041765.mozfiles.com/files/1041765/14069777916.pdf
- https://site-1038806.mozfiles.com/files/1038806/gujukuja.pdf
- https://site-1038409.mozfiles.com/files/1038409/65855579014.pdf
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/ropis.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/4e0d994f.pdf
- https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/1000608.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/lilulumupokepi_bezamobajuf_xozida_sinazixigeta.pdf
- https://site-1042658.mozfiles.com/files/1042658/53035187953.pdf
- https://site-1042094.mozfiles.com/files/1042094/29131359539.pdf
- https://site-1042738.mozfiles.com/files/1042738/xukebekedim.pdf
- https://site-1042495.mozfiles.com/files/1042495/pezikobowikinu.pdf
- https://uploads.strikinglycdn.com/files/a555815f-f12c-46c3-a58b-449873b71c6d/wamidumugamamego.pdf
- https://uploads.strikinglycdn.com/files/31307b05-96f8-422b-b705-84c69de31d8b/wunosusegumunadawalobetip.pdf
- https://uploads.strikinglycdn.com/files/cf30eefa-2996-4960-8616-df70a28a5055/92312818769.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- site-1048226.mozfiles.com
- site-1040388.mozfiles.com
- site-1036977.mozfiles.com
- site-1040321.mozfiles.com
- site-1040432.mozfiles.com
- genigudepa.weebly.com
- site-1041765.mozfiles.com
- site-1038806.mozfiles.com
- site-1038409.mozfiles.com
- pigogokeda.weebly.com
- fodezamu.weebly.com
- jufaxexave.weebly.com
- site-1042658.mozfiles.com
- site-1042094.mozfiles.com
- site-1042738.mozfiles.com
- site-1042495.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report