MALICIOUS — e6092c_1a0d67e6c75b40f3b569d096c8c9b187.pdf
MALICIOUS — e6092c_1a0d67e6c75b40f3b569d096c8c9b187.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (78/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
33cca373c6fecb153745e699d465090ad9d373d0e9f662ce5a27c66df7d71253 - SHA-1:
7bd1515203fbf010e7eb47abd832ca9a5d7b4b69 - MD5:
0518f740615db2489b0520e93043739e - ssdeep:
768:2gGzpDcXLPlQowiAwynPOoVunAgN0As3:jGFgJunPOoVuARAs3 - TLSH:
T11A31AFF351A7ED4C76CA6F57AEAA115DB045E64D7036A69019CC3B2CC0BC3EC6E40A24 - Submitted as: e6092c_1a0d67e6c75b40f3b569d096c8c9b187.pdf
- File type: pdf · Size: 41698 bytes
- Verdict: malicious (78/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 78/100 is the fusion of 5 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.com/wix?keyword=transcribeme+audio+exam+answers+july+2020, https://0fa96eaf-e02c-4867-8cf3-d30680208650.filesusr.com/ugd/3e7897_eb4d8a6a6666451b8b0a9daf7091cbfa.pdf?index=true, https://2257b51c-348c-4c34-b56e-99865b9764f3.filesusr.com/ugd/95089d_6b461c5d9b2244769153b2b8cf208459.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/wix?keyword=transcribeme+audio+exam+answers+july+2020
- https://0fa96eaf-e02c-4867-8cf3-d30680208650.filesusr.com/ugd/3e7897_eb4d8a6a6666451b8b0a9daf7091cbfa.pdf?index=true
- https://2257b51c-348c-4c34-b56e-99865b9764f3.filesusr.com/ugd/95089d_6b461c5d9b2244769153b2b8cf208459.pdf?index=true
- https://7e966814-f776-4151-a480-b546ff034d6c.filesusr.com/ugd/43d598_cfd6598f285440b5825c8a2d5bd9260b.pdf?index=true
- https://0a2812a3-cbad-4ce6-9a65-b415bdb4cdbb.filesusr.com/ugd/a2de88_91f58f61bc2d4fcb8f9b5b55db6312fc.pdf?index=true
- https://44f24d45-34a9-4ba7-a56a-88e22cf2b90a.filesusr.com/ugd/b0b521_a9b811b01b8c41988e804b93a1aaa9ef.pdf?index=true
- https://870698a2-4e05-4e86-8d14-2b7790669147.filesusr.com/ugd/3eb4bd_ef55e3d0260145a0b4abba627c9130d3.pdf?index=true
- https://c76fa012-3d87-4048-a688-06688eecf015.filesusr.com/ugd/dcc11b_353147da7977440dab7d855f685af839.pdf?index=true
- https://8e0d41e6-7719-4638-b8ac-025023c7b232.filesusr.com/ugd/3db607_efb4917eb2e2465e825aa96a95388c9f.pdf?index=true
- https://7ef6ea99-c2a0-4ae2-9f9b-57cbcaea7b7b.filesusr.com/ugd/e2b09b_70d7027fd23b447589f4720eb79b1ea5.pdf?index=true
- https://e93beb5e-46ed-4091-a7c6-223cfdd67a8a.filesusr.com/ugd/d90490_72a92638ff3547789839f80a66c1cf67.pdf?index=true
- https://cdn.shopify.com/s/files/1/0439/7016/6942/files/11287439327.pdf
- https://cdn.shopify.com/s/files/1/0465/3341/0975/files/zixowavoper.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- 0fa96eaf-e02c-4867-8cf3-d30680208650.filesusr.com
- 2257b51c-348c-4c34-b56e-99865b9764f3.filesusr.com
- 7e966814-f776-4151-a480-b546ff034d6c.filesusr.com
- 0a2812a3-cbad-4ce6-9a65-b415bdb4cdbb.filesusr.com
- 44f24d45-34a9-4ba7-a56a-88e22cf2b90a.filesusr.com
- 870698a2-4e05-4e86-8d14-2b7790669147.filesusr.com
- c76fa012-3d87-4048-a688-06688eecf015.filesusr.com
- 8e0d41e6-7719-4638-b8ac-025023c7b232.filesusr.com
- 7ef6ea99-c2a0-4ae2-9f9b-57cbcaea7b7b.filesusr.com
- e93beb5e-46ed-4091-a7c6-223cfdd67a8a.filesusr.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report