MALICIOUS — zomewilaz.pdf
MALICIOUS — zomewilaz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100). 1 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ce8ac55b081828527ca24211df8c7570f187cde82319dcf8265c17fa714bc7ef - SHA-1:
f4a13083e9153391473c4d0e4a98f575a879203d - MD5:
1424786e137b244e23fb1e0b38855ed1 - ssdeep:
768:BgGzpDOpW5ySKijbzuHn8xm2w+ICH660ZqZPLePD:yGFCpWM4ICHEGePD - TLSH:
T1BE306CF350B7ED8C39CB9B03BDEA19598189DB4C61239BA08498673CD47C7BD6E01960 - Submitted as: zomewilaz.pdf
- File type: pdf · Size: 36746 bytes
- Verdict: malicious (71/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Embedded link rated malicious by URL analysis: https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/5648329.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=cuisinart%20coffee%20maker%20manual, https://site-1039830.mozfiles.com/files/1039830/62565292431.pdf, https://site-1043260.mozfiles.com/files/1043260/indicators_of_development.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=cuisinart%20coffee%20maker%20manual
- https://site-1039830.mozfiles.com/files/1039830/62565292431.pdf
- https://site-1043260.mozfiles.com/files/1043260/indicators_of_development.pdf
- https://site-1043759.mozfiles.com/files/1043759/economic_order_quantity_eoq.pdf
- https://site-1043884.mozfiles.com/files/1043884/29960201600.pdf
- https://site-1037054.mozfiles.com/files/1037054/wumajuzilutotisol.pdf
- https://uploads.strikinglycdn.com/files/b62e81ce-138e-4a92-b841-07f8e5874b35/lonozab.pdf
- https://uploads.strikinglycdn.com/files/3f8da701-8e64-47bb-b3ee-b84000fa29c3/paturuwojizenus.pdf
- https://xebikazogede.weebly.com/uploads/1/3/2/7/132740990/9384386.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/5648329.pdf
- https://mijisurux.weebly.com/uploads/1/3/1/0/131070147/xalurawi.pdf
- https://polabufasol.weebly.com/uploads/1/3/2/8/132814050/1dad00ade338b1.pdf
- https://cdn.shopify.com/s/files/1/0429/4646/1855/files/natokujamezewep.pdf
- https://cdn.shopify.com/s/files/1/0496/4987/7143/files/89645733495.pdf
- https://cdn-cms.f-static.net/uploads/4366637/normal_5f8729a4c0c04.pdf
- https://cdn-cms.f-static.net/uploads/4365606/normal_5f873ceac9704.pdf
- https://cdn-cms.f-static.net/uploads/4368240/normal_5f888b98b2bb7.pdf
- https://cdn-cms.f-static.net/uploads/4367312/normal_5f887439a83c4.pdf
- https://uploads.strikinglycdn.com/files/6cbadd6a-fba6-40c5-913f-6a5ced2d2d19/sefakusi.pdf
- https://uploads.strikinglycdn.com/files/9876006f-ea67-458f-a573-9d6d78d0b4b0/xaxevij.pdf
- https://uploads.strikinglycdn.com/files/faa6635a-266c-4679-8f55-e5d1323cd580/mogilavuz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- site-1039830.mozfiles.com
- site-1043260.mozfiles.com
- site-1043759.mozfiles.com
- site-1043884.mozfiles.com
- site-1037054.mozfiles.com
- uploads.strikinglycdn.com
- xebikazogede.weebly.com
- fijojonibiw.weebly.com
- mijisurux.weebly.com
- polabufasol.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report