MALICIOUS — 740d8c_384f82c72aa242e4b55e407b3a387e97.pdf
MALICIOUS — 740d8c_384f82c72aa242e4b55e407b3a387e97.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
378d16ccb4555fc286392e96a1fb395202ae6dbe4b66af2ddc08679e0cc6b439 - SHA-1:
f3672de132764b05391a4a1d4d51e3cebd05e6cf - MD5:
7030f107de6217c722d45504ea4f0860 - ssdeep:
768:NugGzpDR9Z3lElCVqV4Rw7gbFRvlRcy2ywX7GzTwunHQUWHopB1DRPrjsGgJAY4J:1GF9f36b4RiGDRN2H6zBnH9RB1DVrQGD - TLSH:
T12533AEB351ABCD8C7AC2A7136EAA24185156DA8D213395B409D8773CC8BC3BDBF44960 - Submitted as: 740d8c_384f82c72aa242e4b55e407b3a387e97.pdf
- File type: pdf · Size: 47867 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.club/wix?keyword=mortal+kombat+x+android+hack+free+download, http://tezigeti.46north.ca/uploads/1/3/0/7/130740517/bogaj_wizibirime_vowomosipi_riwewori.pdf, http://fivame.aubertsairedales.com/uploads/1/3/0/7/130739835/kenogutud.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/wix?keyword=mortal+kombat+x+android+hack+free+download
- http://tezigeti.46north.ca/uploads/1/3/0/7/130740517/bogaj_wizibirime_vowomosipi_riwewori.pdf
- http://fivame.aubertsairedales.com/uploads/1/3/0/7/130739835/kenogutud.pdf
- http://files.aileenfletcher.com/uploads/1/3/0/8/130874284/6426254.pdf
- http://files.cos-medics.com/uploads/1/3/0/9/130969371/miwogole-xewekagejalo-getavexen-vadedoxinatuzut.pdf
- http://files.southgeorgiaelitecheer.com/uploads/1/3/1/6/131607404/c462882.pdf
- https://7c8bfc6a-5158-4c43-a792-f6bb8122b648.filesusr.com/ugd/e50c99_e6418d7ccdd54010aeef84fd86b39645.pdf?index=true
- https://0963cdd3-cda2-4801-8f99-831f3ca158a1.filesusr.com/ugd/b926a8_56d5fc32355141e9934c3124a1a4f4db.pdf?index=true
- http://files.makergirlz.org/uploads/1/3/0/7/130738548/zetoki.pdf
- http://dawigo.justinedaisuke.com/uploads/1/3/2/6/132695780/2b81ae5d.pdf
- https://1bf10450-84e3-4c07-a57c-8a5c57bc7457.filesusr.com/ugd/622218_43205bb1cfae404e808dc14fb35ce4fd.pdf?index=true
- https://53d4b280-8447-4d63-bfff-377262d3e267.filesusr.com/ugd/b916f4_429e9256c4b041dca8911b11786462b4.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.club
- tezigeti.46north.ca
- fivame.aubertsairedales.com
- files.aileenfletcher.com
- files.cos-medics.com
- files.southgeorgiaelitecheer.com
- 7c8bfc6a-5158-4c43-a792-f6bb8122b648.filesusr.com
- 0963cdd3-cda2-4801-8f99-831f3ca158a1.filesusr.com
- files.makergirlz.org
- dawigo.justinedaisuke.com
- 1bf10450-84e3-4c07-a57c-8a5c57bc7457.filesusr.com
- 53d4b280-8447-4d63-bfff-377262d3e267.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report