MALICIOUS — vabiwopimif.pdf
MALICIOUS — vabiwopimif.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
c8130aa1ccbcb8a362f567f96450687bd12ed8a694397633137fef4eea124b1b - SHA-1:
4c87d20c31dbceb32e87c54da300bc1562ece7af - MD5:
e138990516f24321a0b0fc1306781085 - ssdeep:
768:DgGzpDsFetcchPgM1QS936sbktzodPW5YGSv7OJ1xXsHKPKCqsm+P:8GF4ZMd2tzoZWYZzOJ1xyCqsmE - TLSH:
T17532AEF75087ED8C7A87AB076DBB0194218AD3882173EB6145C8376CD1BC6BDBE50821 - Submitted as: vabiwopimif.pdf
- File type: pdf · Size: 45536 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.PDF.Agent.gen (rule
HEUR:Trojan.PDF.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://gettraff.ru/strik?keyword=augmented+reality+in+education+pdf, https://cdn.shopify.com/s/files/1/0480/7757/0212/files/dexelodagifojugabinadu.pdf, https://cdn.shopify.com/s/files/1/0482/5248/5786/files/pirate_bays_proxy_2018.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=augmented+reality+in+education+pdf
- https://cdn.shopify.com/s/files/1/0480/7757/0212/files/dexelodagifojugabinadu.pdf
- https://cdn.shopify.com/s/files/1/0482/5248/5786/files/pirate_bays_proxy_2018.pdf
- https://cdn.shopify.com/s/files/1/0464/7383/8750/files/37396304107.pdf
- https://uploads.strikinglycdn.com/files/a96c7180-7268-45b3-b403-572be0b6989c/80701086935.pdf
- https://uploads.strikinglycdn.com/files/1c837fb2-cf1b-482d-965d-11baa6e06447/2111694034.pdf
- https://uploads.strikinglycdn.com/files/6d25dcfa-1260-4883-9bde-e2caf64d48aa/8359710763.pdf
- https://uploads.strikinglycdn.com/files/930341c7-3f88-4e5d-ab7a-aa6d1ff7f0b3/64216955052.pdf
- https://uploads.strikinglycdn.com/files/3f1931c2-8bf1-47f7-abca-ec257161c4ea/86212290347.pdf
- https://cdn.shopify.com/s/files/1/0428/5464/5916/files/47328885768.pdf
- https://cdn.shopify.com/s/files/1/0436/0096/9890/files/sample_permission_letter_to_be_absent_from_work.pdf
- https://cdn.shopify.com/s/files/1/0429/3863/0300/files/eurovan_repair_manual.pdf
- https://site-1037260.mozfiles.com/files/1037260/nolugosunugu.pdf
- https://site-1037178.mozfiles.com/files/1037178/fasonuxopulemip.pdf
- https://site-1037102.mozfiles.com/files/1037102/8349217879.pdf
- https://site-1036699.mozfiles.com/files/1036699/47079722422.pdf
- https://site-1036786.mozfiles.com/files/1036786/24174042019.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1037260.mozfiles.com
- site-1037178.mozfiles.com
- site-1037102.mozfiles.com
- site-1036699.mozfiles.com
- site-1036786.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report