MALICIOUS — 8b49c6_afae4425fa4a4080a845dd5d816d0bb2.pdf
MALICIOUS — 8b49c6_afae4425fa4a4080a845dd5d816d0bb2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
489425f5ca7a26e6dcdf226ea9358a75a4f40c42d6f36fff3f0c6e1786937f75 - SHA-1:
d2c18bfd0ee724d068903a4aeec464620132afd2 - MD5:
b4c04e5781ccb21b9fb6c1b549723213 - ssdeep:
768:/gGzpDZCywApC5E93AHbU1ZPab4inn0YApCwRva3SUMU64xeVmYm0UCva:IGFNWewE9Tvab4W/e4MUCva - TLSH:
T127339EF35197DD8C369A9F13AEA6042A6085EACD6137DB501888772CC47C7FDBE10A21 - Submitted as: 8b49c6_afae4425fa4a4080a845dd5d816d0bb2.pdf
- File type: pdf · Size: 48889 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.com/wix?keyword=jane+eyre+chapter+1+questions+and+answers, http://pirudifo.phoenixlegacyofcompassion.org/uploads/1/3/0/8/130874655/4993800.pdf, http://files.lumbercityfarmday.org/uploads/1/3/2/6/132681426/bovixezezarow_dalisudime_bubafuribed.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/wix?keyword=jane+eyre+chapter+1+questions+and+answers
- http://pirudifo.phoenixlegacyofcompassion.org/uploads/1/3/0/8/130874655/4993800.pdf
- http://files.lumbercityfarmday.org/uploads/1/3/2/6/132681426/bovixezezarow_dalisudime_bubafuribed.pdf
- http://sumiw.cachevalleyresources.org/uploads/1/3/1/6/131606349/tonapemixez.pdf
- http://files.ruinsofmodernity.com/uploads/1/3/2/8/132814977/mubuvuzuriw-miligute-visexuriwodi-midovetawa.pdf
- http://files.taitfarmfoods.com/uploads/1/3/1/4/131438069/lumuxumugez.pdf
- http://files.touchofhaven.ca/uploads/1/3/0/9/130969148/kagewapuliz-kiwekeso.pdf
- http://dosozogaz.goldaes.com/uploads/1/3/1/3/131378950/606088.pdf
- http://files.gratiotdems.net/uploads/1/3/2/6/132683088/zatiligakozi.pdf
- https://8b19e99c-f1ca-4470-b8ce-f61ff9744cdf.filesusr.com/ugd/11b39a_a25f603a5c934738b48fb2191ed96850.pdf?index=true
- https://ceee61a8-d7df-4eb6-acab-7f93f2cf7b72.filesusr.com/ugd/8a05ec_1ad9cb3e78a44a0ab0a43bc2170feb0d.pdf?index=true
- https://cdn.shopify.com/s/files/1/0433/6487/6444/files/juwafowalapiv.pdf
- https://cdn.shopify.com/s/files/1/0449/4236/0744/files/apnea_obstructiva_del_sueo_medigraphic.pdf
- https://cdn.shopify.com/s/files/1/0431/8520/9512/files/august_monthly_calendar.pdf
- https://cdn.shopify.com/s/files/1/0429/1729/8329/files/african_american_studies_textbook.pdf
- https://cdn.shopify.com/s/files/1/0429/9217/3217/files/xusokiwunikaze.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- pirudifo.phoenixlegacyofcompassion.org
- files.lumbercityfarmday.org
- sumiw.cachevalleyresources.org
- files.ruinsofmodernity.com
- files.taitfarmfoods.com
- files.touchofhaven.ca
- dosozogaz.goldaes.com
- files.gratiotdems.net
- 8b19e99c-f1ca-4470-b8ce-f61ff9744cdf.filesusr.com
- ceee61a8-d7df-4eb6-acab-7f93f2cf7b72.filesusr.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report