MALICIOUS — fafumugamibifon.pdf
MALICIOUS — fafumugamibifon.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d89b0ba7d546cf78f607448894e0df098a496517c81f71e2365cd59ac38a98f8 - SHA-1:
4f75e2f2ed7a440a0f556755417db55ab917a888 - MD5:
a2dcdce5838152b2eda61226500bd038 - ssdeep:
768:vgGzpDIpStz0MgGotXryxIdbdw99Qgu4sDZtye9PJRNX:YGF0pUzXo9yOti9Xu4Kme9JrX - TLSH:
T11A328CF300E3ED8CBB8B9F439CAB169A508AD348A13AC794455C772C85BC5AE7F10851 - Submitted as: fafumugamibifon.pdf
- File type: pdf · Size: 46563 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://lasajiboz.weebly.com/uploads/1/3/1/3/131379041/fa6cd6acf.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=piramides%20ecologicas%20tipos, https://lasajiboz.weebly.com/uploads/1/3/1/3/131379041/fa6cd6acf.pdf, https://lodirunesu.weebly.com/uploads/1/3/0/8/130874391/8358579.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=piramides%20ecologicas%20tipos
- https://lasajiboz.weebly.com/uploads/1/3/1/3/131379041/fa6cd6acf.pdf
- https://lodirunesu.weebly.com/uploads/1/3/0/8/130874391/8358579.pdf
- https://viwuwobigoku.weebly.com/uploads/1/3/1/3/131378942/juniwotusupuvafodif.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/safado-fodidunixoso.pdf
- https://vagonegasix.weebly.com/uploads/1/3/1/4/131482995/kufutukiw-gujixonek.pdf
- https://berajuvexoru.weebly.com/uploads/1/3/1/8/131860787/gutofuwofuva.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/xewuj.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/simebojesoraro-legabuzu-jivilidoparogi.pdf
- https://nobinetezo.weebly.com/uploads/1/3/0/9/130969761/tupoxit.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/7447336.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/36ce75ac.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/xududev-ledavodu-jatulivarolaxe-bixebenal.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/d96ddb407408.pdf
- https://worobewunit.weebly.com/uploads/1/3/1/4/131406731/26267e507.pdf
- https://uploads.strikinglycdn.com/files/c570ca8e-d01c-425d-aa3d-f791e87865a2/jifemuwokaronefer.pdf
- https://uploads.strikinglycdn.com/files/02777fae-8729-4bb9-81cc-831cd3d03586/1152562396.pdf
- https://uploads.strikinglycdn.com/files/8f546e28-2d45-46ff-b2e1-864ef42c64a2/kuralirelilos.pdf
- https://uploads.strikinglycdn.com/files/bf7e14fb-9953-4a05-9797-ab553ce588ab/36511072804.pdf
- https://uploads.strikinglycdn.com/files/3fe20162-56a1-4398-a531-f0825d3f4fb0/63463405222.pdf
- https://site-1048275.mozfiles.com/files/1048275/16215661602.pdf
- https://site-1042343.mozfiles.com/files/1042343/31506429925.pdf
- https://site-1039885.mozfiles.com/files/1039885/73359618444.pdf
- https://site-1039132.mozfiles.com/files/1039132/68538142162.pdf
- https://site-1039902.mozfiles.com/files/1039902/49116177845.pdf
Embedded domains
- gettraff.ru
- lasajiboz.weebly.com
- lodirunesu.weebly.com
- viwuwobigoku.weebly.com
- dimaxafazeza.weebly.com
- vagonegasix.weebly.com
- berajuvexoru.weebly.com
- bedizegoresupa.weebly.com
- jufaxexave.weebly.com
- nobinetezo.weebly.com
- besiwalufeg.weebly.com
- dutitujazekap.weebly.com
- jakedekokobara.weebly.com
- gimejexoxixaza.weebly.com
- worobewunit.weebly.com
- uploads.strikinglycdn.com
- site-1048275.mozfiles.com
- site-1042343.mozfiles.com
- site-1039885.mozfiles.com
- site-1039132.mozfiles.com
- site-1039902.mozfiles.com
- zoveponezewuda.weebly.com
- pepotoxuxomupav.weebly.com
- xojerajap.weebly.com
- mogilifus.weebly.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report