MALICIOUS — 370021_24b039b193994652b67140ceca45868a.pdf
MALICIOUS — 370021_24b039b193994652b67140ceca45868a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
287ce589248037d43a49e66c5d2b9b6a192d9532289473655843963009074ba6 - SHA-1:
cfbe67363195c4e75c62e1d1dd870aab22a84bed - MD5:
f0f129b17dda98f20c4be5893ae63f47 - ssdeep:
768:fpgGzpD3MbzUQmNozAsWf0P07MN0xN7XYQqeiU1F9wn95rboFF6yrDR:fKGFbmkCCIN0LYzXU1FA5PS0CR - TLSH:
T169339EF3145BEC8C768A9F07AEAA05546086A3886133977448487BACD47C6FDBF50F60 - Submitted as: 370021_24b039b193994652b67140ceca45868a.pdf
- File type: pdf · Size: 48818 bytes
- Verdict: malicious (88/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.PDF.Agent.gen (rule
HEUR:Trojan.PDF.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.com/wix?keyword=plot+summary+of+if+i+stay, http://gamubudo.djhinton.com/uploads/1/3/0/8/130813985/0e2b25f8.pdf, http://files.theprowlradio.com/uploads/1/3/1/3/131379832/mofusumarasekerovul.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/wix?keyword=plot+summary+of+if+i+stay
- http://gamubudo.djhinton.com/uploads/1/3/0/8/130813985/0e2b25f8.pdf
- http://files.theprowlradio.com/uploads/1/3/1/3/131379832/mofusumarasekerovul.pdf
- http://files.thriftbox.org/uploads/1/3/1/3/131383698/namegi.pdf
- http://files.calvaryalliancehiawassee.org/uploads/1/3/0/7/130776321/fd35173506484ed.pdf
- http://files.rutter-project.org/uploads/1/3/2/3/132302987/kenotegasi.pdf
- https://54a147dc-496f-41d2-ac9c-92f8fc54bf32.filesusr.com/ugd/2e4eb4_014af4a049f84f0aafedcd75c2a970de.pdf?index=true
- https://6c0a4505-6954-4b74-81af-1b3127721675.filesusr.com/ugd/668a47_411eb8746e174cb1a5deb65feaae35be.pdf?index=true
- https://b7b40d3d-7a25-44ca-bce3-af655b28404f.filesusr.com/ugd/c83fdb_d33387ffffb641089be0d04d7c16c8c0.pdf?index=true
- https://5cd3eeca-e40a-4d38-b1bc-6955b037462a.filesusr.com/ugd/6cf0f5_938a9833c9144b4bb77b9ea99262145c.pdf?index=true
- https://65e5a1fe-a40b-4e91-9582-0287c95bb15a.filesusr.com/ugd/f4de5e_4e6f3f1bc89f4e028a150617cc405783.pdf?index=true
- https://67e9317f-b2d8-440a-9734-40aef0f61b9c.filesusr.com/ugd/0d018b_906bf9564efd4861a41c18938caa9986.pdf?index=true
- https://9905952b-a71d-4b86-ad50-22ba09231c6d.filesusr.com/ugd/3ed902_b9fcd049bd5e4a4fa6a1357f49380d31.pdf?index=true
- https://edad6f84-9f9b-42b8-b092-1ca78fdb8ac6.filesusr.com/ugd/48bf55_3884317cb92f4e64aea0a61217a11acf.pdf?index=true
- https://99e406d8-1660-473e-a2f1-0c81a6127ff6.filesusr.com/ugd/f1780b_19aee13574934b0ea3f046eb76007513.pdf?index=true
- https://317f3fce-5236-4046-81e7-6131b5ea316a.filesusr.com/ugd/f1780b_4a25bf261ed5491fb96a863c191951f2.pdf?index=true
- https://f09c942c-df50-485e-af9e-7e2511a09ed6.filesusr.com/ugd/3ed902_d519895f0e654193889de36e7cb23eb0.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- gamubudo.djhinton.com
- files.theprowlradio.com
- files.thriftbox.org
- files.calvaryalliancehiawassee.org
- files.rutter-project.org
- 54a147dc-496f-41d2-ac9c-92f8fc54bf32.filesusr.com
- 6c0a4505-6954-4b74-81af-1b3127721675.filesusr.com
- b7b40d3d-7a25-44ca-bce3-af655b28404f.filesusr.com
- 5cd3eeca-e40a-4d38-b1bc-6955b037462a.filesusr.com
- 65e5a1fe-a40b-4e91-9582-0287c95bb15a.filesusr.com
- 67e9317f-b2d8-440a-9734-40aef0f61b9c.filesusr.com
- 9905952b-a71d-4b86-ad50-22ba09231c6d.filesusr.com
- edad6f84-9f9b-42b8-b092-1ca78fdb8ac6.filesusr.com
- 99e406d8-1660-473e-a2f1-0c81a6127ff6.filesusr.com
- 317f3fce-5236-4046-81e7-6131b5ea316a.filesusr.com
- f09c942c-df50-485e-af9e-7e2511a09ed6.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report