MALICIOUS — d7d6cd_bf56019035724bed93c220e0cd34fd42.pdf
MALICIOUS — d7d6cd_bf56019035724bed93c220e0cd34fd42.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
0b813e02a23bb953af837e228252c6473f677ff44f0f2b9ea3e22f2a8153417c - SHA-1:
a7df78e0d97e95c95a51f6dbfbdbcc725e92b2a1 - MD5:
fc0dd7e54676c3a6424e04d7e0a8a195 - ssdeep:
768:EgGzpDGaWT5ki9UBJgn3ghGgCalvthzjOrbzgZK6FLIRWMJRPlXbJ:xGFi7tUBJgn3ghGapXCbOFLIRWqRPlXl - TLSH:
T12C329EF75067DE8C3E8BAF037DA60188A086D788712656B015D8B76CD8B86FD7F00951 - Submitted as: d7d6cd_bf56019035724bed93c220e0cd34fd42.pdf
- File type: pdf · Size: 47214 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.link/wix?keyword=area+of+a+rhombus+worksheet, http://webaf.elisemitchellcoaching.com/uploads/1/3/1/6/131606279/2e937206e2.pdf, http://supefuvab.phillipsandphillipsmusic.com/uploads/1/3/0/8/130813694/jexufasawumakevatane.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/wix?keyword=area+of+a+rhombus+worksheet
- http://webaf.elisemitchellcoaching.com/uploads/1/3/1/6/131606279/2e937206e2.pdf
- http://supefuvab.phillipsandphillipsmusic.com/uploads/1/3/0/8/130813694/jexufasawumakevatane.pdf
- http://kotifug.buckysactionfiguretheater.com/uploads/1/3/1/8/131871453/e7361d07.pdf
- https://59adf9db-3a38-44a0-b2f2-7814e37cd020.filesusr.com/ugd/625844_da0eb2ec45674a26ba2268267aa9b82f.pdf?index=true
- https://ed57cfd6-ad8d-43fa-9f16-f4bb94bba532.filesusr.com/ugd/dc8a8e_235864fb0c274cbc9e6883c4fc520cc5.pdf?index=true
- https://70e69bd2-3356-44ec-9d52-819c085a2cf5.filesusr.com/ugd/45fd81_e69e9ce641324aa5ba7c1fa595853c17.pdf?index=true
- https://f0b1a799-9599-4a4d-8239-f5856cdd7c6f.filesusr.com/ugd/c450b2_9ba20297fa244b21ac0e7abdb86096bb.pdf?index=true
- http://kazif.ftjbymelissa.com/uploads/1/3/0/7/130776542/803e7589.pdf
- http://jiluzuwox.rotolomusic.com/uploads/1/3/0/9/130969604/subetigudan.pdf
- https://d49f40c3-add2-43eb-b1d6-d4c8024c4722.filesusr.com/ugd/4725f1_31eb936613be45fea79524e97ddf3c9a.pdf?index=true
- https://92d57ef1-3ddb-446e-a267-82dc643b3641.filesusr.com/ugd/c5d40f_198c9412e5da4afc8681b0676a058098.pdf?index=true
- https://9571c3e8-f003-44a3-9454-5d2b9c6cec59.filesusr.com/ugd/3be48b_d19cd23021284b58a80f2947f4ad23c9.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.link
- webaf.elisemitchellcoaching.com
- supefuvab.phillipsandphillipsmusic.com
- kotifug.buckysactionfiguretheater.com
- 59adf9db-3a38-44a0-b2f2-7814e37cd020.filesusr.com
- ed57cfd6-ad8d-43fa-9f16-f4bb94bba532.filesusr.com
- 70e69bd2-3356-44ec-9d52-819c085a2cf5.filesusr.com
- f0b1a799-9599-4a4d-8239-f5856cdd7c6f.filesusr.com
- kazif.ftjbymelissa.com
- jiluzuwox.rotolomusic.com
- d49f40c3-add2-43eb-b1d6-d4c8024c4722.filesusr.com
- 92d57ef1-3ddb-446e-a267-82dc643b3641.filesusr.com
- 9571c3e8-f003-44a3-9454-5d2b9c6cec59.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report