MALICIOUS — jitavajugizoxon.pdf
MALICIOUS — jitavajugizoxon.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c38b9878a61a67b9efcda2fecc1e3ec91ff28e117012bcc99530b2e2b4e5437f - SHA-1:
0bbd635be42c40541e33d2d0ddc041a8c260a82a - MD5:
c07f82ce8a737c241a6a7a85c7a3a3bd - ssdeep:
768:HgGzpDFpIycM7HA7hD93u/yIx92812276/tI0loL:AGFxpvxgY2276q0loL - TLSH:
T1C2307EF35097EC8C3A8B5B03ADA7259D608EC74C613697B0449C7A2DC47CAAD7E019A0 - Submitted as: jitavajugizoxon.pdf
- File type: pdf · Size: 36656 bytes
- Verdict: malicious (75/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://cdn-cms.f-static.net/uploads/4365601/normal_5f87177226f73.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=nissan+teana+2020+owners+manual+pdf, https://cdn-cms.f-static.net/uploads/4365601/normal_5f87177226f73.pdf, https://cdn-cms.f-static.net/uploads/4366041/normal_5f87195f395f8.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=nissan+teana+2020+owners+manual+pdf
- https://cdn-cms.f-static.net/uploads/4365601/normal_5f87177226f73.pdf
- https://cdn-cms.f-static.net/uploads/4366041/normal_5f87195f395f8.pdf
- https://cdn-cms.f-static.net/uploads/4369152/normal_5f88c42d30c63.pdf
- https://uploads.strikinglycdn.com/files/e9b723e4-e2c3-432d-b51b-0b52b897344d/kexusekitiwada.pdf
- https://uploads.strikinglycdn.com/files/36814fa5-143a-4118-b484-d57230d2a409/90665740858.pdf
- https://uploads.strikinglycdn.com/files/aea703bb-5249-477a-b247-731ec2cb2975/87438830878.pdf
- https://uploads.strikinglycdn.com/files/b4fb8456-7024-4025-a8fd-fe45408c6da6/walusozafujos.pdf
- https://buliduxefexefux.weebly.com/uploads/1/3/1/6/131636978/zuberojo.pdf
- https://lokixesope.weebly.com/uploads/1/3/1/6/131607163/zubatosibolan_zororu_vikepeb_lujuxu.pdf
- https://cdn.shopify.com/s/files/1/0501/0056/8221/files/setozekigux.pdf
- https://cdn.shopify.com/s/files/1/0266/7905/0438/files/hustle_castle_apkpure.pdf
- https://cdn.shopify.com/s/files/1/0484/8395/8945/files/magic_mill_food_dehydrator_recipes.pdf
- https://cdn.shopify.com/s/files/1/0431/9209/0784/files/chrome_bar_stools_walmart.pdf
- https://site-1039153.mozfiles.com/files/1039153/firorujigutazur.pdf
- https://site-1040242.mozfiles.com/files/1040242/48140904124.pdf
- https://site-1036753.mozfiles.com/files/1036753/95810118807.pdf
- https://site-1039515.mozfiles.com/files/1039515/kabekexatodajudinukepa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- buliduxefexefux.weebly.com
- lokixesope.weebly.com
- cdn.shopify.com
- site-1039153.mozfiles.com
- site-1040242.mozfiles.com
- site-1036753.mozfiles.com
- site-1039515.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report