MALICIOUS — bikufegomed.pdf
MALICIOUS — bikufegomed.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f88aab8aa01a2270c82a61a7dfb661abd58962750b3052b328761d1f89704759 - SHA-1:
8c57f8eb0d97d29e0c1b0b66a026dfe9fddbee3a - MD5:
2bc7b778bca391371da53ff6021f4daa - ssdeep:
1536:1GF3cIZqC8qxlpvuLZX2/zaeAayWWtNC2lJ:IF3YCxKlXYoarWtNC2 - TLSH:
T18C337BB32097ED4CB6B66F436E97006A6D49C278713F96E0489C266CCDEC29D6E1081D - Submitted as: bikufegomed.pdf
- File type: pdf · Size: 50144 bytes
- Verdict: malicious (75/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/9b53ec72f.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=jvc%20gr-sxm240%20manual, https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/9b53ec72f.pdf, https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/tugunari_fogeze_nezejavoz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=jvc%20gr-sxm240%20manual
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/9b53ec72f.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/tugunari_fogeze_nezejavoz.pdf
- https://rokufekajo.weebly.com/uploads/1/3/0/8/130814342/gomikowuveridoxemes.pdf
- https://wejibuxod.weebly.com/uploads/1/3/0/7/130740202/40e281cff9.pdf
- https://cdn.shopify.com/s/files/1/0435/2661/9287/files/70977714962.pdf
- https://cdn.shopify.com/s/files/1/0497/4120/1562/files/5008460736.pdf
- https://cdn.shopify.com/s/files/1/0502/9344/0697/files/chronological_resume_example.pdf
- https://cdn.shopify.com/s/files/1/0432/0319/9138/files/11562951998.pdf
- https://cdn-cms.f-static.net/uploads/4389601/normal_5f905fa064b76.pdf
- https://cdn-cms.f-static.net/uploads/4381546/normal_5f8d53e6d8616.pdf
- https://cdn-cms.f-static.net/uploads/4366050/normal_5f89a3cf2e737.pdf
- https://cdn-cms.f-static.net/uploads/4381962/normal_5f8f35e46351e.pdf
- https://xiletepegokif.weebly.com/uploads/1/3/4/3/134319576/fuxafe.pdf
- https://tejigenunonim.weebly.com/uploads/1/3/0/8/130813632/diwutebugabajip.pdf
- https://lajojixuvoporor.weebly.com/uploads/1/3/0/7/130738555/tobador.pdf
- https://rabugotekinevod.weebly.com/uploads/1/3/1/8/131871666/c9440356.pdf
- https://cdn.shopify.com/s/files/1/0434/3562/2552/files/lippincott_manual_of_nursing_practice_9th_ed._lippincott_williams__wilkins.pdf
- https://cdn.shopify.com/s/files/1/0481/6093/1991/files/the_selection_kiera_cass.pdf
- https://cdn-cms.f-static.net/uploads/4365549/normal_5f8710e2797b5.pdf
- https://cdn-cms.f-static.net/uploads/4366973/normal_5f8eedd0c66e8.pdf
- https://cdn-cms.f-static.net/uploads/4366004/normal_5f8b308e8ac25.pdf
- https://cdn-cms.f-static.net/uploads/4368958/normal_5f87e440906fc.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- mogilifus.weebly.com
- guwomenod.weebly.com
- rokufekajo.weebly.com
- wejibuxod.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- xiletepegokif.weebly.com
- tejigenunonim.weebly.com
- lajojixuvoporor.weebly.com
- rabugotekinevod.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report