MALICIOUS — e3ed1f_11189da295ec4722890858c5f4aaf18b.pdf
MALICIOUS — e3ed1f_11189da295ec4722890858c5f4aaf18b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
46110e4ccc99126b922e5795b555733864803cc2c12170deb8e42460ff192e9e - SHA-1:
d3669488c7ddd4745c425fbd952c1ad0a9c0f19b - MD5:
77d17ed1f205f8a036a0648437c5fb31 - ssdeep:
1536:dGFkkjW11ZqKOK8D/DuoXmHmmmtXV+/O:gFkQWB5G/vi6XVB - TLSH:
T1E633C0F354ABDD8C3AC667039CA71199608AC6CD1236A76048DC3B7CE0BC5BDBD50961 - Submitted as: e3ed1f_11189da295ec4722890858c5f4aaf18b.pdf
- File type: pdf · Size: 49844 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.PDF.Agent.gen (rule
HEUR:Trojan.PDF.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.link/wix?keyword=dragon+city+hack+apk+download, https://00c49d5e-099b-46b4-bbdf-d5fd8bea5b40.filesusr.com/ugd/ea2f88_0a791021ff794ca2aa8e7a3e78fffb06.pdf?index=true, https://2f501b19-c78b-4fc1-8591-cc18b1b45c16.filesusr.com/ugd/fe83c3_5990d0e8935a4dc0aa554224d45e4fa1.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/wix?keyword=dragon+city+hack+apk+download
- https://00c49d5e-099b-46b4-bbdf-d5fd8bea5b40.filesusr.com/ugd/ea2f88_0a791021ff794ca2aa8e7a3e78fffb06.pdf?index=true
- https://2f501b19-c78b-4fc1-8591-cc18b1b45c16.filesusr.com/ugd/fe83c3_5990d0e8935a4dc0aa554224d45e4fa1.pdf?index=true
- https://f8f71357-fc5b-43e8-a225-b35b700faed3.filesusr.com/ugd/bb4607_ee389285a42d4b69960930caf92bb44f.pdf?index=true
- https://1b399463-634a-4fc2-8dff-f854bad8a84d.filesusr.com/ugd/d1c05f_9ad6880e4c6d400abce49a54922110db.pdf?index=true
- https://46267842-a334-4e59-ada6-ef7837e79ae1.filesusr.com/ugd/f96b02_7031a883984e4c2b9312c46a014a7d48.pdf?index=true
- https://cdn.shopify.com/s/files/1/0435/5080/2081/files/billetes_didacticos_colombianos_para_imprimir.pdf
- https://cdn.shopify.com/s/files/1/0439/2203/0760/files/pubg_mobile_hack_iphone.pdf
- https://cdn.shopify.com/s/files/1/0438/9978/1288/files/maleg.pdf
- https://cdn.shopify.com/s/files/1/0484/6030/0442/files/ragijewiboxofosuj.pdf
- https://cdn.shopify.com/s/files/1/0441/0913/6024/files/92826634811.pdf
- https://cdn.shopify.com/s/files/1/0429/2290/1663/files/24129823626.pdf
- https://cdn.shopify.com/s/files/1/0465/4769/7814/files/56398181172.pdf
- https://cdn.shopify.com/s/files/1/0438/5321/7952/files/apple_tv_program_guide.pdf
- https://3bd873a8-a758-4e61-b4a6-91f666030a10.filesusr.com/ugd/008e52_42d31643f6f5424baee54d7ba3589f2a.pdf?index=true
- https://6d59d793-7dae-4e0c-9d67-f0a701e509c7.filesusr.com/ugd/e6092c_6f8a793df583405aa976294de0492cb7.pdf?index=true
- https://95a61955-ba9f-413a-bd0b-2bed8ec23fda.filesusr.com/ugd/bc4951_caeccfc45609409dbbe0f26e8abc0a87.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.link
- 00c49d5e-099b-46b4-bbdf-d5fd8bea5b40.filesusr.com
- 2f501b19-c78b-4fc1-8591-cc18b1b45c16.filesusr.com
- f8f71357-fc5b-43e8-a225-b35b700faed3.filesusr.com
- 1b399463-634a-4fc2-8dff-f854bad8a84d.filesusr.com
- 46267842-a334-4e59-ada6-ef7837e79ae1.filesusr.com
- cdn.shopify.com
- 3bd873a8-a758-4e61-b4a6-91f666030a10.filesusr.com
- 6d59d793-7dae-4e0c-9d67-f0a701e509c7.filesusr.com
- 95a61955-ba9f-413a-bd0b-2bed8ec23fda.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report