MALICIOUS — ef0078_33a91ae7fa64453f83235c70f23cce1d.pdf
MALICIOUS — ef0078_33a91ae7fa64453f83235c70f23cce1d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
25c33fc743d388e787b785debb251dceb95f1d7745ba2e30d382ce638cee11a2 - SHA-1:
03a4f1e84a8c754c1bc54ebcdba607a856af53e3 - MD5:
93c641efaa88bbdecbf6860d0bf1b182 - ssdeep:
768:3gGzpDvgya+hft4PpjypZ5y4ntlMqsBMw5sJT9taRr:QGF7SPpjypZY+tiqsBzs3taRr - TLSH:
T19D307DF35497DC8C3ACBEB03ADE62155618AC7897133DB6048987B6CC4BC2BC6E50961 - Submitted as: ef0078_33a91ae7fa64453f83235c70f23cce1d.pdf
- File type: pdf · Size: 37939 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.club/wix?keyword=sdsu+spring+2020+catalog, http://files.theirisharthistorian.com/uploads/1/3/1/4/131438460/7866956.pdf, http://goxokul.joyhakim.com/uploads/1/3/0/7/130775350/b9a59a3.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/wix?keyword=sdsu+spring+2020+catalog
- http://files.theirisharthistorian.com/uploads/1/3/1/4/131438460/7866956.pdf
- http://goxokul.joyhakim.com/uploads/1/3/0/7/130775350/b9a59a3.pdf
- http://files.unitedwayofpc.org/uploads/1/3/2/6/132683289/gijigasufedezit.pdf
- https://11d5d060-dfb4-4c9d-8e58-365d7bd81433.filesusr.com/ugd/cfa91a_428ee7ec78b147f6b3c819a8e28d496e.pdf?index=true
- https://e0e90f87-bab3-426e-9219-9663ca894a42.filesusr.com/ugd/9c8fb9_8ebaad82e0044708a22efdbf3a6f6b79.pdf?index=true
- https://654334cb-920d-49e2-a733-24cc8d82dfdb.filesusr.com/ugd/e3ff21_dbfbc7bd4ec940f09b7fe0cdefd41cc2.pdf?index=true
- https://e0e7978e-926c-4545-b274-75e36dd1a343.filesusr.com/ugd/c068f8_14bd50d40d144cb3ac2e8bab0245e869.pdf?index=true
- https://cdn.shopify.com/s/files/1/0439/4565/6488/files/ribixaxuvoroxedutoso.pdf
- https://cdn.shopify.com/s/files/1/0431/4578/9600/files/53587621822.pdf
- https://cdn.shopify.com/s/files/1/0427/7141/5196/files/2012_kia_forte_repair_manual.pdf
- https://cdn.shopify.com/s/files/1/0432/2947/9072/files/pdf_eraser_download_free.pdf
- https://cdn.shopify.com/s/files/1/0433/4478/9669/files/geruf.pdf
- https://1102ffb3-6457-4311-b15c-69f16e5c9a0f.filesusr.com/ugd/e4ff69_1aacf4f1eedd4e1680667f7b5e671fc2.pdf?index=true
- https://859bd51d-8fe5-47e5-89aa-58e82ac72479.filesusr.com/ugd/17159d_93501b964bc041419f12797708b98675.pdf?index=true
- https://9fc0ee08-7aad-4d36-b06a-7802bc747c9f.filesusr.com/ugd/ce0e6d_bbfe601dc16348ed952ee70cb2d41c1f.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.club
- files.theirisharthistorian.com
- goxokul.joyhakim.com
- files.unitedwayofpc.org
- 11d5d060-dfb4-4c9d-8e58-365d7bd81433.filesusr.com
- e0e90f87-bab3-426e-9219-9663ca894a42.filesusr.com
- 654334cb-920d-49e2-a733-24cc8d82dfdb.filesusr.com
- e0e7978e-926c-4545-b274-75e36dd1a343.filesusr.com
- cdn.shopify.com
- 1102ffb3-6457-4311-b15c-69f16e5c9a0f.filesusr.com
- 859bd51d-8fe5-47e5-89aa-58e82ac72479.filesusr.com
- 9fc0ee08-7aad-4d36-b06a-7802bc747c9f.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report