MALICIOUS — c5d40f_7cfbdff050284834a70a0ec36c440092.pdf
MALICIOUS — c5d40f_7cfbdff050284834a70a0ec36c440092.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
2a166b394dbace4c6f884600da1f7516c3e1d315139f2550e5a38d00ccac873e - SHA-1:
4a2fecf1a3eb03552b77e106763490783b8bf372 - MD5:
4dbcddb61c78cb6d8722c1c13c24a76b - ssdeep:
768:UgGzpDg6Yp/FFJueR5n66N0C3HrtE1q+zWOKFGCNVIF2kP9d:hGFkNF4eRt6ZCCq+zW9FGCNVIUkP9d - TLSH:
T15F329EF72097DD8C39DB8B03AEE52618A546E6493033A67094D87B3CC4B87BDAE11950 - Submitted as: c5d40f_7cfbdff050284834a70a0ec36c440092.pdf
- File type: pdf · Size: 44750 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.cc/wix?keyword=tv+themes+ringtones+for+mobile+phones, https://32dad5d5-d0f3-4db0-8d09-203847dc3fd1.filesusr.com/ugd/682d1c_44c055d5481649879e40037c24cf6aee.pdf?index=true, https://cd0d4083-0406-491f-912d-c3fc55791231.filesusr.com/ugd/b463f2_10a3f81de7324bf7813d75898f8465fa.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/wix?keyword=tv+themes+ringtones+for+mobile+phones
- https://32dad5d5-d0f3-4db0-8d09-203847dc3fd1.filesusr.com/ugd/682d1c_44c055d5481649879e40037c24cf6aee.pdf?index=true
- https://cd0d4083-0406-491f-912d-c3fc55791231.filesusr.com/ugd/b463f2_10a3f81de7324bf7813d75898f8465fa.pdf?index=true
- https://ae903360-c417-4d0a-878f-171f0352b056.filesusr.com/ugd/7e0eb0_3a77769d2e034e949947b717a0b587ab.pdf?index=true
- https://315b1b77-d0dc-4968-9afb-2c8d4bfc7e3b.filesusr.com/ugd/4b874d_df98042170954bda8cba6999418f0fbc.pdf?index=true
- http://files.drone-novice.com/uploads/1/3/1/8/131857626/vutevajenulo.pdf
- http://files.sid1.org/uploads/1/3/1/6/131606069/domakorapoz_karefox_senuvexuxagaki.pdf
- https://8f33a481-cece-4811-a6d6-28cedb1a338b.filesusr.com/ugd/110ef3_4e9286fb94054995b45370bf38904395.pdf?index=true
- https://ebdba004-485a-4991-940e-28a587d4b264.filesusr.com/ugd/110ef3_652ff2d997a04f4f93e959b880e9b11d.pdf?index=true
- https://ef78ec8c-8275-47af-9a5d-bd9a59ea8425.filesusr.com/ugd/f08e01_26e02e46d7cb43e0a226deb19efa7275.pdf?index=true
- https://3d7d24aa-142d-4dd4-9436-5c17ddd0cbdd.filesusr.com/ugd/3ed902_d279033596604201bebdba632a4b7f94.pdf?index=true
- https://b2c14109-dd99-4b7a-acec-67c53db98608.filesusr.com/ugd/682d1c_fa75d9b0fe2f4e64a7092a2ea531401a.pdf?index=true
- https://dfaea684-0161-4832-9be4-019ac2122973.filesusr.com/ugd/035627_67db7286de11465fb13619d6740468b5.pdf?index=true
- https://dfc2da15-3e06-4407-8d79-034527622b2c.filesusr.com/ugd/ced2dc_21558a20ef244c47ad60450a04b9b229.pdf?index=true
- https://4e2bd541-a0de-4997-a109-176b0faff25a.filesusr.com/ugd/69695d_358f25d4cce648e49c7e557145f8454c.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.cc
- 32dad5d5-d0f3-4db0-8d09-203847dc3fd1.filesusr.com
- cd0d4083-0406-491f-912d-c3fc55791231.filesusr.com
- ae903360-c417-4d0a-878f-171f0352b056.filesusr.com
- 315b1b77-d0dc-4968-9afb-2c8d4bfc7e3b.filesusr.com
- files.drone-novice.com
- files.sid1.org
- 8f33a481-cece-4811-a6d6-28cedb1a338b.filesusr.com
- ebdba004-485a-4991-940e-28a587d4b264.filesusr.com
- ef78ec8c-8275-47af-9a5d-bd9a59ea8425.filesusr.com
- 3d7d24aa-142d-4dd4-9436-5c17ddd0cbdd.filesusr.com
- b2c14109-dd99-4b7a-acec-67c53db98608.filesusr.com
- dfaea684-0161-4832-9be4-019ac2122973.filesusr.com
- dfc2da15-3e06-4407-8d79-034527622b2c.filesusr.com
- 4e2bd541-a0de-4997-a109-176b0faff25a.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report