MALICIOUS — 227d0f_63ebafa0bbdf4d47963f465820a2ef80.pdf
MALICIOUS — 227d0f_63ebafa0bbdf4d47963f465820a2ef80.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
4c954073ff64c80caa8f8e73844aa843a8cff66ada0a9540c193922c1c665fbd - SHA-1:
5b4f20686a69a79119a87be104b2a0a5e6977a64 - MD5:
a286c758bdf55030ea1b146da0228bef - ssdeep:
1536:PGFcngXQFDj3dl3uQ97IFi70D0M9jUGigjjUePLff8:+Fcngojn35OoKwZSUeTfE - TLSH:
T12B35BFF350E7ED8C3A8E1F07A9E60819A09AC64C343697B444DA762CD5787EC6F10E15 - Submitted as: 227d0f_63ebafa0bbdf4d47963f465820a2ef80.pdf
- File type: pdf · Size: 57867 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=hurdy+gurdy+key+box+plans, http://files.tkccv.net/uploads/1/3/1/4/131437074/c03aa12e3399.pdf, http://files.solsticevocalarts.com/uploads/1/3/0/8/130873855/xonejivuvezuk-rigegaruxop-xireli.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/wix?keyword=hurdy+gurdy+key+box+plans
- http://files.tkccv.net/uploads/1/3/1/4/131437074/c03aa12e3399.pdf
- http://files.solsticevocalarts.com/uploads/1/3/0/8/130873855/xonejivuvezuk-rigegaruxop-xireli.pdf
- http://files.faceeffect.shop/uploads/1/3/2/6/132695535/b6c82b8c7f826.pdf
- http://files.quantumologist.net/uploads/1/3/1/4/131454986/3bd6363.pdf
- http://xunab.teaandtango.com/uploads/1/3/2/7/132740214/xozezubopezobej.pdf
- https://0d512472-f808-11ea-a328-fc4dd43d38a6.filesusr.com/ugd/017c44_9160600306b848a2a2db36b99484c8b8.pdf?index=true
- https://028f61b6-f808-11ea-a328-fc4dd43d38a6.filesusr.com/ugd/fd4c29_ea0b973a3d7b48e0a8a7cf27a6255490.pdf?index=true
- https://713e02f1-8b89-46e7-82ac-d8a141405aea.filesusr.com/ugd/e948c1_153f425d41c34e0a9d32be8cd03e6801.pdf?index=true
- https://f6e319a4-713a-483d-b235-f73977ff8f3b.filesusr.com/ugd/974a4e_5a74700a305941d9a01613f9387fe289.pdf?index=true
- http://files.revdenisetracy.com/uploads/1/3/0/7/130739227/ledisifuk.pdf
- http://files.apexgki.com/uploads/1/3/0/8/130874284/delorunefufewem_bexililat_vesipixa.pdf
- https://1f7757ca-f808-11ea-a328-fc4dd43d38a6.filesusr.com/ugd/5ccfc8_84a2f4303a114b63840edb0748c495db.pdf?index=true
- https://588c4f28-f06e-4085-882e-939ca294e987.filesusr.com/ugd/c722c2_396cdfae73114d20885f57f9881c3eb0.pdf?index=true
- https://f915a33e-f807-11ea-a328-fc4dd43d38a6.filesusr.com/ugd/9ef0c3_4541a83cf6a3405ca5ea10b951df6fe5.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- files.tkccv.net
- files.solsticevocalarts.com
- files.faceeffect.shop
- files.quantumologist.net
- xunab.teaandtango.com
- 0d512472-f808-11ea-a328-fc4dd43d38a6.filesusr.com
- 028f61b6-f808-11ea-a328-fc4dd43d38a6.filesusr.com
- 713e02f1-8b89-46e7-82ac-d8a141405aea.filesusr.com
- f6e319a4-713a-483d-b235-f73977ff8f3b.filesusr.com
- files.revdenisetracy.com
- files.apexgki.com
- 1f7757ca-f808-11ea-a328-fc4dd43d38a6.filesusr.com
- 588c4f28-f06e-4085-882e-939ca294e987.filesusr.com
- f915a33e-f807-11ea-a328-fc4dd43d38a6.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report