MALICIOUS — mujimojepesisuvimejazelo.pdf
MALICIOUS — mujimojepesisuvimejazelo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
c421177de47a0e5be3901c1abcefcc9bb8c180c76de4a802c336a7631a752d3c - SHA-1:
5d06eca851e9ffaf16ec60a744e95ae687d8abf1 - MD5:
57f0d9e19a0add8e5ef0451713dff440 - ssdeep:
768:NgGzpDfcUVKa3fv2KQeVHUqkjXi6MMix5U2Obk0sveJnB5HD2wcTr:uGFzg/gAqnURiM32wcTr - TLSH:
T15F34BEF3A067FC8C2B8A6707A9A311592105D78C613797A068D47B3CC4BC6FDAE40B61 - Submitted as: mujimojepesisuvimejazelo.pdf
- File type: pdf · Size: 52336 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ggtraff.ru/strik?keyword=aeration+tank+pdf, https://site-1036830.mozfiles.com/files/1036830/69643804366.pdf, https://site-1036724.mozfiles.com/files/1036724/nilameket.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=aeration+tank+pdf
- https://site-1036830.mozfiles.com/files/1036830/69643804366.pdf
- https://site-1036724.mozfiles.com/files/1036724/nilameket.pdf
- https://site-1037009.mozfiles.com/files/1037009/vakujozemap.pdf
- https://site-1036946.mozfiles.com/files/1036946/37285637355.pdf
- http://files.luluanthistle.com/uploads/1/3/1/8/131856195/9171686.pdf
- http://files.jewelsofafrica.org/uploads/1/3/2/8/132814031/414375.pdf
- http://files.starviewucc.org/uploads/1/3/0/7/130739871/buxojowoma.pdf
- http://files.samhallsport.com/uploads/1/3/1/3/131384284/6974305.pdf
- http://denasolol.nicolelancaster.com/uploads/1/3/1/4/131406970/silejipalukakopuwiv.pdf
- http://files.youngsvillelibrary.org/uploads/1/3/0/7/130740148/1ae03f353d22.pdf
- https://cdn.shopify.com/s/files/1/0431/0161/8330/files/bhojpuri_video_hd_song.pdf
- https://cdn.shopify.com/s/files/1/0437/4455/9258/files/silk_browser_fr_android_tv.pdf
- https://cdn.shopify.com/s/files/1/0429/1035/1513/files/competence_and_performance_by_chomsky.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1036830.mozfiles.com
- site-1036724.mozfiles.com
- site-1037009.mozfiles.com
- site-1036946.mozfiles.com
- files.luluanthistle.com
- files.jewelsofafrica.org
- files.starviewucc.org
- files.samhallsport.com
- denasolol.nicolelancaster.com
- files.youngsvillelibrary.org
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report