MALICIOUS — 610d21_91ca048b762047c3930c14c4fb6dd06f.pdf
MALICIOUS — 610d21_91ca048b762047c3930c14c4fb6dd06f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (78/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
25a80384c2fd15a9f8c3a034b849e95bb7d69bb34b24a95192434b4a274d1020 - SHA-1:
a119c19b1435f1a013b1f50de0fc998f986f422d - MD5:
1e783d042633674fa8de7d29f6d90e1a - ssdeep:
768:XgGzpD2EA676SWhO5GoyLkSBPlSPWec7U5KE5b3l:wGF61j9V/oc7eKE5b3l - TLSH:
T1D42F8DF32067EC8C3A8F6B43ADE7114A6596D2C96036E760198D3B6CD47C6AC7F10A50 - Submitted as: 610d21_91ca048b762047c3930c14c4fb6dd06f.pdf
- File type: pdf · Size: 33903 bytes
- Verdict: malicious (78/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 78/100 is the fusion of 5 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.me/wix?keyword=provas+da+uva+comentadas, https://cdn.shopify.com/s/files/1/0428/5959/3894/files/xamebidabuwojuze.pdf, https://cdn.shopify.com/s/files/1/0434/5459/5224/files/robunivajakitu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/wix?keyword=provas+da+uva+comentadas
- https://cdn.shopify.com/s/files/1/0428/5959/3894/files/xamebidabuwojuze.pdf
- https://cdn.shopify.com/s/files/1/0434/5459/5224/files/robunivajakitu.pdf
- https://cdn.shopify.com/s/files/1/0440/8036/5720/files/fobibixiwarupodo.pdf
- https://f165d463-b1b0-4b8b-a3f9-1102f3e0c2a0.filesusr.com/ugd/d2759c_ca37865ee71544aa83eec0b781d15581.pdf?index=true
- https://15783b36-dfb9-4985-98aa-aacf8cafcc27.filesusr.com/ugd/f08e01_4846cf75986a4b6cb8384929c66e3659.pdf?index=true
- https://281c2068-2cb7-4bea-aa25-8af251d63042.filesusr.com/ugd/49f5ef_226430cc219e4bb7944fbf07e017296b.pdf?index=true
- https://e8598a7e-3f5b-40db-a920-2e1eebc7e54e.filesusr.com/ugd/4c7633_d7463374f38649e39a156924a5883bb8.pdf?index=true
- http://files.makergirlz.org/uploads/1/3/0/7/130739564/05095d01439.pdf
- http://vazili.nhcohousing.com/uploads/1/3/1/0/131070705/nagetanokew_fusumaleneli.pdf
- https://cdn.shopify.com/s/files/1/0463/3709/7889/files/likes_and_dislikes_worksheet_for_beginners.pdf
- https://cdn.shopify.com/s/files/1/0447/9670/6967/files/wijekijuvofe.pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/kepikopu.pdf
- https://cdn.shopify.com/s/files/1/0432/8187/5104/files/czasy_angielski_wiczenia_szkoa_podstawowa.pdf
- https://cdn.shopify.com/s/files/1/0436/3229/6089/files/accounting_concepts_download.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.me
- cdn.shopify.com
- f165d463-b1b0-4b8b-a3f9-1102f3e0c2a0.filesusr.com
- 15783b36-dfb9-4985-98aa-aacf8cafcc27.filesusr.com
- 281c2068-2cb7-4bea-aa25-8af251d63042.filesusr.com
- e8598a7e-3f5b-40db-a920-2e1eebc7e54e.filesusr.com
- files.makergirlz.org
- vazili.nhcohousing.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report