MALICIOUS — 6f53d7_5db98e5813c941c6b98e4cfef51e0a74.pdf
MALICIOUS — 6f53d7_5db98e5813c941c6b98e4cfef51e0a74.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
4474bc73cbfaff979b33d2b617f8bfbe25040e4aed154be52af447b4a5a7b52a - SHA-1:
2f76b88ad98e52f585cdd6bfb7fc26cdc79fefc6 - MD5:
d7572e4fa5ddf32373e79c014d8b3816 - ssdeep:
768:lgGzpDlU6bUmKkgrXU2Jao4ydQaN2skgb4p2fxsuwo:2GFJWX3GydQa0s9b4wGuwo - TLSH:
T181329DF391ABECCCAA4A5F07ADA61148B405D68D3032736048DD763CD8BC6EC6E509B5 - Submitted as: 6f53d7_5db98e5813c941c6b98e4cfef51e0a74.pdf
- File type: pdf · Size: 43445 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.com/wix?keyword=honeywell+thermostat+tb7220u1012+manual, https://8007b120-de4e-41a0-9897-0d4b86086788.filesusr.com/ugd/2f7815_c2ae15c29bdc4210aa810f8ce1e6af1b.pdf?index=true, https://ac4976b2-4e06-4b17-803b-ab7946844c28.filesusr.com/ugd/594ae5_24b56b768ef8404f92c11e0cc994b75b.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/wix?keyword=honeywell+thermostat+tb7220u1012+manual
- https://8007b120-de4e-41a0-9897-0d4b86086788.filesusr.com/ugd/2f7815_c2ae15c29bdc4210aa810f8ce1e6af1b.pdf?index=true
- https://ac4976b2-4e06-4b17-803b-ab7946844c28.filesusr.com/ugd/594ae5_24b56b768ef8404f92c11e0cc994b75b.pdf?index=true
- https://69ee534a-8943-4302-998d-41dc03830b9b.filesusr.com/ugd/c79b1c_307d1055a2454d7fa8a6fdc6b93594d9.pdf?index=true
- https://8496119b-30b7-4f3f-94d1-1510522d5f09.filesusr.com/ugd/5bb01c_0dfe8496ddab4755a6711baf5faec18d.pdf?index=true
- http://lozivugif.13moonvisions.com/uploads/1/3/0/9/130969176/cb1ce.pdf
- http://files.gapco.online/uploads/1/3/0/8/130874284/vofinopoteto.pdf
- http://files.freemap.nl/uploads/1/3/0/8/130874257/fedeferejago_kuwugaxifeba.pdf
- https://6bdd5864-22b8-4630-9867-5800277afbfa.filesusr.com/ugd/3f0e57_f70f170d4385436f81424beb90ccc429.pdf?index=true
- https://9269322b-fc9f-4e05-ac04-880ba55b734f.filesusr.com/ugd/d2751c_527db70e33d74f83af133dc38e3b8c7f.pdf?index=true
- https://4bdeadfd-8588-41e7-b157-dbfbae86ff09.filesusr.com/ugd/48bf55_76a092e82d694663967bfbf61ddf2446.pdf?index=true
- https://b2191893-6add-4d1f-baaf-bfce371334a4.filesusr.com/ugd/bdc04d_fa739d9396ed4263b2b3814a825d88cf.pdf?index=true
- https://e6356322-7580-4945-851e-9fb8aea4881a.filesusr.com/ugd/370ea2_80db8562471d4522b81b8a35c43c7b62.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- 8007b120-de4e-41a0-9897-0d4b86086788.filesusr.com
- ac4976b2-4e06-4b17-803b-ab7946844c28.filesusr.com
- 69ee534a-8943-4302-998d-41dc03830b9b.filesusr.com
- 8496119b-30b7-4f3f-94d1-1510522d5f09.filesusr.com
- lozivugif.13moonvisions.com
- files.gapco.online
- files.freemap.nl
- 6bdd5864-22b8-4630-9867-5800277afbfa.filesusr.com
- 9269322b-fc9f-4e05-ac04-880ba55b734f.filesusr.com
- 4bdeadfd-8588-41e7-b157-dbfbae86ff09.filesusr.com
- b2191893-6add-4d1f-baaf-bfce371334a4.filesusr.com
- e6356322-7580-4945-851e-9fb8aea4881a.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report