MALICIOUS — lamid.pdf
MALICIOUS — lamid.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bb7a29ece36a42a78728bca8e6d109e994c9af197ef722328ed602921439ef04 - SHA-1:
d67fd9789f2c9f39705400abec36a8740e8597b2 - MD5:
a89bb100ea418214951b006480dbc1a0 - ssdeep:
768:3gGzpDUpiAalxDKEJTuXDp0LX6/iufXzbcmfE+Qfyl4s1rryLUDVf85yl/oh3:QGFQpiRKEREbNf0Oh1re4DVk5yl/oh3 - TLSH:
T122326DF350A7ED4C768F6B07AEA7115A508ED38D6136DB900088672CD4BCAED7F11A21 - Submitted as: lamid.pdf
- File type: pdf · Size: 46925 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/sijuwoxujupid.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=free%20editable%20business%20model%20canvas%20powerpoint%20template, https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/sijuwoxujupid.pdf, https://tavumake.weebly.com/uploads/1/3/2/7/132740551/fafajaxunej_fifuxosuw_jilapowebemibi_rabadu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=free%20editable%20business%20model%20canvas%20powerpoint%20template
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/sijuwoxujupid.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/fafajaxunej_fifuxosuw_jilapowebemibi_rabadu.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/4106527.pdf
- https://rimesozarabef.weebly.com/uploads/1/3/1/6/131607712/belatujuvotetozix.pdf
- https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/zamupudebomimaze.pdf
- https://cdn-cms.f-static.net/uploads/4365539/normal_5f8703591a485.pdf
- https://cdn-cms.f-static.net/uploads/4365620/normal_5f874e2332352.pdf
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f8711694521e.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f872d5f8e44e.pdf
- https://cdn-cms.f-static.net/uploads/4367313/normal_5f8757cfc8db1.pdf
- https://site-1039965.mozfiles.com/files/1039965/fupas.pdf
- https://site-1040002.mozfiles.com/files/1040002/47053221020.pdf
- https://site-1041076.mozfiles.com/files/1041076/jezasijoso.pdf
- https://site-1039597.mozfiles.com/files/1039597/vodudaw.pdf
- https://site-1041173.mozfiles.com/files/1041173/vesifenidajinavuvon.pdf
- https://uploads.strikinglycdn.com/files/bbe90885-2619-4d53-b2d6-62512204d4ef/betemujirusaxedufideribob.pdf
- https://uploads.strikinglycdn.com/files/75dab3e6-63b8-4cca-acfc-1ffe19b980cf/3671196419.pdf
- https://uploads.strikinglycdn.com/files/ef735718-8ec6-4888-ae59-2f099820fea0/simefi.pdf
- https://uploads.strikinglycdn.com/files/107e3961-11aa-43de-b569-575a4c976ec0/zemanep.pdf
- https://uploads.strikinglycdn.com/files/a79b6809-881b-4e39-8d66-c48e756f6577/98012057391.pdf
- https://site-1043690.mozfiles.com/files/1043690/90397786997.pdf
- https://site-1036920.mozfiles.com/files/1036920/kodurubo.pdf
- https://site-1039525.mozfiles.com/files/1039525/26766070643.pdf
- https://site-1038338.mozfiles.com/files/1038338/detizosopemov.pdf
Embedded domains
- gettraff.ru
- jatorogerujew.weebly.com
- tavumake.weebly.com
- fijojonibiw.weebly.com
- rimesozarabef.weebly.com
- pumowurunumig.weebly.com
- cdn-cms.f-static.net
- site-1039965.mozfiles.com
- site-1040002.mozfiles.com
- site-1041076.mozfiles.com
- site-1039597.mozfiles.com
- site-1041173.mozfiles.com
- uploads.strikinglycdn.com
- site-1043690.mozfiles.com
- site-1036920.mozfiles.com
- site-1039525.mozfiles.com
- site-1038338.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report