MALICIOUS — d6af85_f3e126c82ee848cd84b25b361727f791.pdf
MALICIOUS — d6af85_f3e126c82ee848cd84b25b361727f791.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
125b8e78f64e6ddffd84070b4aec0a6eda3c55d0e27722d11da19494b4461c7e - SHA-1:
f2e40788d6dbae94b3cbce66f6bfaf763077ec4a - MD5:
1b48dd6d2c4ea385b2574920c8bb703a - ssdeep:
768:ngGzpDSH0F/u7ZhtKAW1W0IPVfPJQFBdRx3F5oNefMqeT/QW9:gGFWo1W0IPJP67x3oNwMqEQW9 - TLSH:
T11E339EF314D7DD8C7A8A9B135CA71159658AD38CA136AB6044DCBB6CD47C2ECAE10E20 - Submitted as: d6af85_f3e126c82ee848cd84b25b361727f791.pdf
- File type: pdf · Size: 47997 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=kearsarge+regional+school+district+salaries, http://pivoxuma.newteachersretreat.com/uploads/1/3/2/6/132682717/sitotozok_fugamowigaran_nagidiwolenofi_todanogepu.pdf, http://bubewa.heartitudeartsoul.com/uploads/1/3/2/7/132712415/wasaxo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/wix?keyword=kearsarge+regional+school+district+salaries
- http://pivoxuma.newteachersretreat.com/uploads/1/3/2/6/132682717/sitotozok_fugamowigaran_nagidiwolenofi_todanogepu.pdf
- http://bubewa.heartitudeartsoul.com/uploads/1/3/2/7/132712415/wasaxo.pdf
- http://fixoteru.apronattitudes.com/uploads/1/3/1/4/131438641/goxapose.pdf
- http://files.beginesl.com/uploads/1/3/0/9/130969327/6558855.pdf
- http://kunupunus.rescuedfirewood.com/uploads/1/3/1/3/131383541/3829052.pdf
- https://cdn.shopify.com/s/files/1/0427/8085/2383/files/wondershare_video_converter_mac.pdf
- https://cdn.shopify.com/s/files/1/0438/6881/5528/files/grade_11_chemistry_book.pdf
- https://cdn.shopify.com/s/files/1/0436/9681/6282/files/ielts_band_9_essays.pdf
- https://cdn.shopify.com/s/files/1/0428/1057/2966/files/57936209108.pdf
- https://01dbf5a0-6041-49b2-b7b1-6dc0f12b3335.filesusr.com/ugd/dcf9ad_5bb9d7224d174eca9e7b7c3aa65d0898.pdf?index=true
- https://17b947f8-44f0-4138-b81c-7e630413ea7d.filesusr.com/ugd/18f527_cb59c87ddc5f4345b0d0f7de2fc311d2.pdf?index=true
- https://9571c3e8-f003-44a3-9454-5d2b9c6cec59.filesusr.com/ugd/3be48b_d19cd23021284b58a80f2947f4ad23c9.pdf?index=true
- https://9dcf42da-17d1-4ae7-9fcd-0e0941380461.filesusr.com/ugd/eb6612_50225242ff1744a1b2dc78c2556e3af3.pdf?index=true
- https://5f475c2c-92ad-4e99-8246-6741821c5aeb.filesusr.com/ugd/5bb01c_e34f2da5f8164d61998e9f1da01c004b.pdf?index=true
- https://cdn.shopify.com/s/files/1/0484/2373/1352/files/white_dog_from_nightmare_before_christmas.pdf
- https://cdn.shopify.com/s/files/1/0462/7169/2951/files/debian_buster_iso.pdf
- https://cdn.shopify.com/s/files/1/0430/7353/6161/files/alaipayuthey_song_free.pdf
- https://cdn.shopify.com/s/files/1/0437/6811/9458/files/artemis_fowl_opal_deception_graphic_novel.pdf
- https://cdn.shopify.com/s/files/1/0446/3240/8227/files/dutenalunuzefafa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ttraff.ru
- pivoxuma.newteachersretreat.com
- bubewa.heartitudeartsoul.com
- fixoteru.apronattitudes.com
- files.beginesl.com
- kunupunus.rescuedfirewood.com
- cdn.shopify.com
- 01dbf5a0-6041-49b2-b7b1-6dc0f12b3335.filesusr.com
- 17b947f8-44f0-4138-b81c-7e630413ea7d.filesusr.com
- 9571c3e8-f003-44a3-9454-5d2b9c6cec59.filesusr.com
- 9dcf42da-17d1-4ae7-9fcd-0e0941380461.filesusr.com
- 5f475c2c-92ad-4e99-8246-6741821c5aeb.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report