MALICIOUS — d1fcfc_1e6e08c6a30c4814ae90305efd9e70ce.pdf
MALICIOUS — d1fcfc_1e6e08c6a30c4814ae90305efd9e70ce.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
267d7706132876da8b811c20a55c2a2960e03a693554cb56f5e4a8c33e45a8c3 - SHA-1:
c1d6d4dfb3cd6308620f928242aac2a64d387a1e - MD5:
f70939c8780b25e443d6d18cf7b2698e - ssdeep:
768:tgGzpD94UTVtttOSYFnc86EgzS/0iUb2PgEEQhlsLyhebhjf179b:OGFJEhcYj0irP1hbahJ79b - TLSH:
T148329EF310DBDC8CBA87AB436D97115A6186D68872369B701988777CD4FC2BDAF00860 - Submitted as: d1fcfc_1e6e08c6a30c4814ae90305efd9e70ce.pdf
- File type: pdf · Size: 46147 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.com/wix?keyword=base.pbp+psx2psp+1.4.2+download, https://cdn.shopify.com/s/files/1/0447/5571/4199/files/25977985784.pdf, https://cdn.shopify.com/s/files/1/0429/0212/6755/files/miwajepaz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/wix?keyword=base.pbp+psx2psp+1.4.2+download
- https://cdn.shopify.com/s/files/1/0447/5571/4199/files/25977985784.pdf
- https://cdn.shopify.com/s/files/1/0429/0212/6755/files/miwajepaz.pdf
- https://cdn.shopify.com/s/files/1/0438/8985/2568/files/52994330192.pdf
- https://cdn.shopify.com/s/files/1/0437/5078/5173/files/appium_android_studio.pdf
- https://ab0b02fc-3404-4b98-a979-f00d238416a1.filesusr.com/ugd/c844bf_d1cabc3d41c846f49733a8b929536dfb.pdf?index=true
- https://0c6cca4c-e00d-423d-8d88-c8d1d77626b6.filesusr.com/ugd/b926a8_017ec09e7ff7497582b02f3d02862786.pdf?index=true
- https://35bbd703-1fe7-43e3-9235-ce7acbf23cb7.filesusr.com/ugd/6cf0f5_503bbfe3c9f54c9bbc02813650b5bdda.pdf?index=true
- https://8cc5255d-054b-4ddc-ad5a-935408048410.filesusr.com/ugd/704988_2bc3e8753aa94a7fb1435cda175bac42.pdf?index=true
- http://sevawuviw.millennialstateofmind.com/uploads/1/3/1/8/131871456/e563509eaabef5b.pdf
- http://runurawe.solereaperz.com/uploads/1/3/1/6/131606490/32f0b1a28cc370.pdf
- http://files.oldsouthart.com/uploads/1/3/0/7/130739024/winefu_mifosefab.pdf
- http://files.destinations-dts.com/uploads/1/3/2/6/132681863/juselogep-mevavetadine-marivivujopanow-fuzumifosobol.pdf
- http://files.aviewoflondon.com/uploads/1/3/1/4/131407351/9d6c68a97451a5.pdf
- https://e26eb81b-f27c-49f7-81f2-8b5149a472ab.filesusr.com/ugd/ed8107_94131d885ca94c55b08bb5841573d8ec.pdf?index=true
- https://be50841d-8c5b-492a-a81c-a765e3cb6b5d.filesusr.com/ugd/04c368_bdc6cc798bc94085b409ac16f065763a.pdf?index=true
- https://f0363792-0d77-4321-9492-d6a4946d2f34.filesusr.com/ugd/370ea2_7875cdf445ce4637998824731fcd557c.pdf?index=true
- https://3f43253e-cba7-4dbc-8bc5-1506630bde1d.filesusr.com/ugd/685707_b747d0be387c4bc0803c2a5b87e2f0fe.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- cdn.shopify.com
- ab0b02fc-3404-4b98-a979-f00d238416a1.filesusr.com
- 0c6cca4c-e00d-423d-8d88-c8d1d77626b6.filesusr.com
- 35bbd703-1fe7-43e3-9235-ce7acbf23cb7.filesusr.com
- 8cc5255d-054b-4ddc-ad5a-935408048410.filesusr.com
- sevawuviw.millennialstateofmind.com
- runurawe.solereaperz.com
- files.oldsouthart.com
- files.destinations-dts.com
- files.aviewoflondon.com
- e26eb81b-f27c-49f7-81f2-8b5149a472ab.filesusr.com
- be50841d-8c5b-492a-a81c-a765e3cb6b5d.filesusr.com
- f0363792-0d77-4321-9492-d6a4946d2f34.filesusr.com
- 3f43253e-cba7-4dbc-8bc5-1506630bde1d.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report