MALICIOUS — wofunasog_bapixoje_siwaj.pdf
MALICIOUS — wofunasog_bapixoje_siwaj.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ceeaecc901c97ce91f1ca07ff74523084a9fcea6c5ce1745938c8686491a04fc - SHA-1:
aad682f579d2d7b5d4147ee96ecb6295bbe55c6f - MD5:
8298e7a95dc9273d16656a842549a6ab - ssdeep:
1536:eGF7ef34i/Xd8fl0IUA59+3SG+XvNYgJhp6Jw8bM:HF7eZVS59cj+fagl2wN - TLSH:
T14D34AEF3109BDD8DBA83AB8369A721656449C3887232D750988C772DD0BC7ADBF10D51 - Submitted as: wofunasog_bapixoje_siwaj.pdf
- File type: pdf · Size: 56385 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://vafumigoku.weebly.com/uploads/1/3/1/3/131384305/918623.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=katherine%20johnson%20biografia%20pdf, https://ziroluberunoreg.weebly.com/uploads/1/3/4/4/134456507/tajegijofiwesav.pdf, https://gejatovuri.weebly.com/uploads/1/3/1/4/131406669/eb5a67.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=katherine%20johnson%20biografia%20pdf
- https://ziroluberunoreg.weebly.com/uploads/1/3/4/4/134456507/tajegijofiwesav.pdf
- https://gejatovuri.weebly.com/uploads/1/3/1/4/131406669/eb5a67.pdf
- https://vafumigoku.weebly.com/uploads/1/3/1/3/131384305/918623.pdf
- https://uploads.strikinglycdn.com/files/789ca987-f06a-4fe8-aa5b-fb46b933c251/xatipoxotozabidowaxomem.pdf
- https://uploads.strikinglycdn.com/files/746512aa-7224-423e-a37d-87a702579047/supprimer_anti_demarrage_megane_1_essence.pdf
- https://uploads.strikinglycdn.com/files/a85973d4-9a19-47e9-9703-2625ee9e6b27/every_good_endeavor_tim_keller.pdf
- https://uploads.strikinglycdn.com/files/38422feb-c839-4789-ba24-7491367b97f9/nombres_relatifs_4me_controle.pdf
- https://cdn-cms.f-static.net/uploads/4387224/normal_5f948653c6825.pdf
- https://cdn-cms.f-static.net/uploads/4383704/normal_5f95ae7f27d8f.pdf
- https://cdn-cms.f-static.net/uploads/4368998/normal_5f8dc07b110ff.pdf
- https://cdn-cms.f-static.net/uploads/4368740/normal_5f886c1903b17.pdf
- https://cdn-cms.f-static.net/uploads/4366984/normal_5f875493bf72f.pdf
- https://cdn.shopify.com/s/files/1/0501/4211/8069/files/banawimajipes.pdf
- https://cdn.shopify.com/s/files/1/0437/6035/3429/files/rac_caravan_insurance.pdf
- https://cdn.shopify.com/s/files/1/0434/4548/5725/files/25862026143.pdf
- https://cdn.shopify.com/s/files/1/0499/9725/0711/files/stryker_gamma_nail_technique_guide.pdf
- https://cdn.shopify.com/s/files/1/0432/2174/5822/files/39317819789.pdf
- https://cdn.shopify.com/s/files/1/0497/9828/3427/files/sbi_yono_apk_download.pdf
- https://cdn.shopify.com/s/files/1/0440/7522/1144/files/povobizegiwudelipuvut.pdf
- https://cdn.shopify.com/s/files/1/0480/7367/0820/files/riluwuputi.pdf
- https://cdn.shopify.com/s/files/1/0482/8761/3096/files/lhasa_apso_poodle_mix_black.pdf
- https://uploads.strikinglycdn.com/files/09d4d93a-ada7-4a1d-8417-4d39378eb0c7/tadomamevuxomiz.pdf
- https://uploads.strikinglycdn.com/files/28319d36-1541-41f8-bea2-4f40652261f3/69564703332.pdf
- https://uploads.strikinglycdn.com/files/4f6a109e-209b-4934-8d6b-9a3db374a773/85777058378.pdf
Embedded domains
- ggtraff.ru
- ziroluberunoreg.weebly.com
- gejatovuri.weebly.com
- vafumigoku.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report