MALICIOUS — 03ae60_7d3f7f312ce34f688267ba9cc7c301ef.pdf
MALICIOUS — 03ae60_7d3f7f312ce34f688267ba9cc7c301ef.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (90/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
071e181face86e11acdf9aeb33e8f430dc57a994c504131b77a6014526bb879f - SHA-1:
47772c718128fb62d47bd018f9b1c4293652878b - MD5:
43ebd9ceb7f3a0578d54e671a589f259 - ssdeep:
768:kgGzpDS7CArXKwOcHj1AeFI09fX+ofo9V3MPpdr6umrOLC3NEjQ8:RGFG7JZxJAWRteV3MPpl6ULMEjQ8 - TLSH:
T1C733AFF340C7DD8C7A8BAF039A9611597042E68D6237ABA45484776CC4FC6BDAF40A31 - Submitted as: 03ae60_7d3f7f312ce34f688267ba9cc7c301ef.pdf
- File type: pdf · Size: 47601 bytes
- Verdict: malicious (90/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 90/100 is the fusion of 6 weighted signals:
- Embedded link rated malicious by URL analysis: https://55c86484-7a67-4f74-adcd-2c799e53ee51.filesusr.com/ugd/c638b7_3775c60f8bca4a53b2cecf319a7065a3.pdf?index=true - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=great+smile+store+electric+toothbrush, https://55c86484-7a67-4f74-adcd-2c799e53ee51.filesusr.com/ugd/c638b7_3775c60f8bca4a53b2cecf319a7065a3.pdf?index=true, https://04c51959-ce30-4b19-8fa4-c0f1b18deb68.filesusr.com/ugd/8bf3fc_6c36e9e079624b64813a104125b3cb87.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/wix?keyword=great+smile+store+electric+toothbrush
- https://55c86484-7a67-4f74-adcd-2c799e53ee51.filesusr.com/ugd/c638b7_3775c60f8bca4a53b2cecf319a7065a3.pdf?index=true
- https://04c51959-ce30-4b19-8fa4-c0f1b18deb68.filesusr.com/ugd/8bf3fc_6c36e9e079624b64813a104125b3cb87.pdf?index=true
- https://f97b6ec8-4fd5-4e5e-afee-125d538911f4.filesusr.com/ugd/143c98_7dfd77ad5eac488290212de9a9d0482e.pdf?index=true
- https://a37ef15f-7918-40cb-9986-11f2a5233a57.filesusr.com/ugd/c83fdb_4f5041de3bf24503bf4466edde9fd52d.pdf?index=true
- https://0d4d10b9-8e97-4419-945e-6b15673e912f.filesusr.com/ugd/17ce20_cbd2828935dc4c89ac2a9bf79c77240d.pdf?index=true
- https://d5a5f824-bbab-412c-acb2-2251fc9faeb5.filesusr.com/ugd/3cb679_9d7f22093c0349e9b43c9af8558ca230.pdf?index=true
- https://d4d7bb64-6e70-4f4e-bc04-a06b8723586b.filesusr.com/ugd/9f06f8_b7f50e0eefbc40c095dd3e50c3b5f5c3.pdf?index=true
- https://48de5127-23ec-4ecc-a68f-6d8f2943a9d5.filesusr.com/ugd/66f3f9_7489839f501a4fe29533eeae70caac06.pdf?index=true
- https://2229d4b9-89d1-4ef1-94f2-21daf137d2fb.filesusr.com/ugd/61b8bf_f3add25c2d144ebeaf4dcfb37c5f5add.pdf?index=true
- https://ce5c0e8b-4502-4a67-b6bb-38a81a9697c7.filesusr.com/ugd/5ea691_7fcb667f0c7646b58e3c9d9d893d4b4f.pdf?index=true
- https://10691afd-eaad-46e1-99fd-2aede6d38ea5.filesusr.com/ugd/f99735_f5bb55ef23ff455693d45bad69df96c2.pdf?index=true
- https://2867e3a4-5af3-407e-8051-bcab6f7dffbd.filesusr.com/ugd/76aeb6_851b968a86fd4309b7537896c09802f6.pdf?index=true
- https://54b6e866-33b5-4fff-b700-68334175a47d.filesusr.com/ugd/9904c2_1890c9d1d483431e9940b1aa858b6637.pdf?index=true
- https://e51f7a8b-726b-4d2e-ae32-a6575443ea8d.filesusr.com/ugd/a4ea6c_010bb53b73aa47968a44e5d8efacf8ed.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- 55c86484-7a67-4f74-adcd-2c799e53ee51.filesusr.com
- 04c51959-ce30-4b19-8fa4-c0f1b18deb68.filesusr.com
- f97b6ec8-4fd5-4e5e-afee-125d538911f4.filesusr.com
- a37ef15f-7918-40cb-9986-11f2a5233a57.filesusr.com
- 0d4d10b9-8e97-4419-945e-6b15673e912f.filesusr.com
- d5a5f824-bbab-412c-acb2-2251fc9faeb5.filesusr.com
- d4d7bb64-6e70-4f4e-bc04-a06b8723586b.filesusr.com
- 48de5127-23ec-4ecc-a68f-6d8f2943a9d5.filesusr.com
- 2229d4b9-89d1-4ef1-94f2-21daf137d2fb.filesusr.com
- ce5c0e8b-4502-4a67-b6bb-38a81a9697c7.filesusr.com
- 10691afd-eaad-46e1-99fd-2aede6d38ea5.filesusr.com
- 2867e3a4-5af3-407e-8051-bcab6f7dffbd.filesusr.com
- 54b6e866-33b5-4fff-b700-68334175a47d.filesusr.com
- e51f7a8b-726b-4d2e-ae32-a6575443ea8d.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report