MALICIOUS — vigosojaxamagetabir.pdf
MALICIOUS — vigosojaxamagetabir.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f137c3f0ae65c058f205d925dd7c8b9256ce6155e5fed9b0c525a6174b2de637 - SHA-1:
76e792f09509290d045e66e08ee01f72e2d74e46 - MD5:
f4ef4cdda5d081698e0036e6e2105213 - ssdeep:
768:CgGzpD/e9uh3aJK42ssNTiG8omEwexPUElDpawjfvB59xdE1loDdq0699u4M+4+t:fGFjeEhqODlDpFjRjG6DQX9uB+jjp - TLSH:
T13D349DF35067ED8C7A879B036DAA245EA049E7896623D79444D8376CC0BC3FC3E11561 - Submitted as: vigosojaxamagetabir.pdf
- File type: pdf · Size: 56323 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/1000608.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=guide%20raccoon%20hv, https://cdn-cms.f-static.net/uploads/4366004/normal_5f8701c8eee62.pdf, https://cdn-cms.f-static.net/uploads/4368503/normal_5f878c0ccdb87.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=guide%20raccoon%20hv
- https://cdn-cms.f-static.net/uploads/4366004/normal_5f8701c8eee62.pdf
- https://cdn-cms.f-static.net/uploads/4368503/normal_5f878c0ccdb87.pdf
- https://cdn-cms.f-static.net/uploads/4367960/normal_5f877f45b0958.pdf
- https://cdn-cms.f-static.net/uploads/4368782/normal_5f88272d729ae.pdf
- https://cdn-cms.f-static.net/uploads/4366632/normal_5f885916e4478.pdf
- https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/1000608.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/zebapesuluboxaj.pdf
- https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/10d616.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/d8065cd0ebc23d.pdf
- https://cdn-cms.f-static.net/uploads/4367308/normal_5f87ff17303c7.pdf
- https://cdn-cms.f-static.net/uploads/4366401/normal_5f875a12b7b7b.pdf
- https://cdn-cms.f-static.net/uploads/4366973/normal_5f880dd4ad23a.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f87460d625ae.pdf
- https://cdn-cms.f-static.net/uploads/4367633/normal_5f874920cb3d3.pdf
- https://cdn.shopify.com/s/files/1/0497/3491/0101/files/18426162705.pdf
- https://cdn.shopify.com/s/files/1/0483/9853/2757/files/ironman_inversion_table_website.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f87174c5a723.pdf
- https://cdn-cms.f-static.net/uploads/4367312/normal_5f874b9f4df7d.pdf
- https://cdn-cms.f-static.net/uploads/4366041/normal_5f8815e75b189.pdf
- https://site-1037906.mozfiles.com/files/1037906/dagulorumubutilabodiji.pdf
- https://site-1041579.mozfiles.com/files/1041579/gevonipi.pdf
- https://site-1048535.mozfiles.com/files/1048535/progressive_overload_training.pdf
- https://site-1039772.mozfiles.com/files/1039772/27929714299.pdf
- https://site-1043032.mozfiles.com/files/1043032/neletujamime.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- fodezamu.weebly.com
- xojerajap.weebly.com
- pumowurunumig.weebly.com
- jufaxexave.weebly.com
- cdn.shopify.com
- site-1037906.mozfiles.com
- site-1041579.mozfiles.com
- site-1048535.mozfiles.com
- site-1039772.mozfiles.com
- site-1043032.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report