MALICIOUS — 22545116851.pdf
MALICIOUS — 22545116851.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
14568708174d6c0a9ee996be943b642ab21fde7bc4c4ffeafa3221dad562ffa9 - SHA-1:
77bfc373a64a146e408fb8958528e78a54731d33 - MD5:
02bdd239126b75b6ea3c00e4c9715eb2 - ssdeep:
384:csFlS3K6XgKV7cAgdOpW+0hL6GDVevL3W9sYvGPsDA5yKGVql9O1IRk2NGa8iuV0:8gGzpDyuGNv/hVqXPkw8tqqW8OS+B - TLSH:
T18A309DF3A057DD9C7AC7AB03ADA31486644AD78D213397A058D8376DC4BC2FC6E40860 - Submitted as: 22545116851.pdf
- File type: pdf · Size: 37013 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://cctraff.ru/strik?keyword=shanti+narayan+differential+calculus+pdf, http://vogave.buceph.com/uploads/1/3/0/8/130813715/gumebusogobewedadiba.pdf, http://fopunux.bao-le.org/uploads/1/3/1/6/131606228/fibav.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=shanti+narayan+differential+calculus+pdf
- http://vogave.buceph.com/uploads/1/3/0/8/130813715/gumebusogobewedadiba.pdf
- http://fopunux.bao-le.org/uploads/1/3/1/6/131606228/fibav.pdf
- http://begupu.newwoodturners.org/uploads/1/3/2/7/132740267/zoboregekalamojaba.pdf
- http://files.sanjoseexpress.org/uploads/1/3/1/3/131379033/6518158.pdf
- http://files.owlingdog.com/uploads/1/3/1/0/131070792/1837627.pdf
- http://files.essenceofblissmassage.com/uploads/1/3/1/3/131378953/77eb0e4e03.pdf
- http://files.hopeshouseworks.ca/uploads/1/3/0/8/130874585/pexekasaveb-vekurud.pdf
- http://files.lizritchie.com/uploads/1/3/1/6/131637656/7192591.pdf
- http://niwaz.cedarvalleysales.com/uploads/1/3/1/8/131856801/mubezose-duropepufodan-podametu.pdf
- http://files.vesnamcmaster.com/uploads/1/3/0/7/130739962/tafus.pdf
- https://site-1036775.mozfiles.com/files/1036775/kokot.pdf
- https://site-1037891.mozfiles.com/files/1037891/jumulixefaze.pdf
- https://site-1036862.mozfiles.com/files/1036862/kepatexavajir.pdf
- https://site-1036728.mozfiles.com/files/1036728/fizojiselas.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- vogave.buceph.com
- fopunux.bao-le.org
- begupu.newwoodturners.org
- files.sanjoseexpress.org
- files.owlingdog.com
- files.essenceofblissmassage.com
- files.hopeshouseworks.ca
- files.lizritchie.com
- niwaz.cedarvalleysales.com
- files.vesnamcmaster.com
- site-1036775.mozfiles.com
- site-1037891.mozfiles.com
- site-1036862.mozfiles.com
- site-1036728.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report