MALICIOUS — 3f80ec_a436ecae222948fc87c88e2ad68c9a9c.pdf
MALICIOUS — 3f80ec_a436ecae222948fc87c88e2ad68c9a9c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
5780714ca95472ce66c16e01b1203fad19c00547021f96d00446f0c31f6f789f - SHA-1:
393e9cd3ff1cbf756dae6fa75568540913f82356 - MD5:
7a9b60ab99b5446ba434422c42f43fe8 - ssdeep:
768:OgGzpDKcPx6ZOn0WR1xBm3HA/nOXVHDBz+/g2a6yo8MErGf5lR:rGF+cJBm3HJXVHDog2co9eGf5lR - TLSH:
T17632BFF3519BFD8C7A8BAB4399E711187085A7C9A02366A001DD7B2CC47C2FC6F50A65 - Submitted as: 3f80ec_a436ecae222948fc87c88e2ad68c9a9c.pdf
- File type: pdf · Size: 44332 bytes
- Verdict: malicious (88/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.PDF.Agent.gen (rule
HEUR:Trojan.PDF.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.me/wix?keyword=where+the+wild+things+are+downloadable+font, https://55cd38ab-cc2f-4ab8-9e9a-181ad073084b.filesusr.com/ugd/3a38e0_63d9a1e4d496425baf055bf406b567fc.pdf?index=true, https://614eeb68-2662-4969-9b84-06020f42efdc.filesusr.com/ugd/b42fd6_dc21950e764140719e3ee4a1f8906d93.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/wix?keyword=where+the+wild+things+are+downloadable+font
- https://55cd38ab-cc2f-4ab8-9e9a-181ad073084b.filesusr.com/ugd/3a38e0_63d9a1e4d496425baf055bf406b567fc.pdf?index=true
- https://614eeb68-2662-4969-9b84-06020f42efdc.filesusr.com/ugd/b42fd6_dc21950e764140719e3ee4a1f8906d93.pdf?index=true
- https://18b3e02f-9920-4307-901c-02899b80f5dd.filesusr.com/ugd/b90ba1_54909734e50d4fc29ad472557d24ce3c.pdf?index=true
- https://357c084e-71e6-40af-8b83-297a8dc89711.filesusr.com/ugd/3283b0_ea3eea5b30f04dda98360a812a6d2c23.pdf?index=true
- https://4ef574a2-fdbf-4519-8610-8677e257b14a.filesusr.com/ugd/d93890_dcb7b2b778c94e908a90cccb2fe6f14f.pdf?index=true
- https://cdn.shopify.com/s/files/1/0457/3619/8300/files/rivawunerofiwoza.pdf
- https://cdn.shopify.com/s/files/1/0429/6487/7475/files/how_to_make_spheres_in_minecraft.pdf
- https://cdn.shopify.com/s/files/1/0428/8439/9270/files/teamwork_essay.pdf
- https://cdn.shopify.com/s/files/1/0432/0290/4222/files/sifejemuf.pdf
- https://cdn.shopify.com/s/files/1/0436/4717/2768/files/jaxemivo.pdf
- https://13fe947d-383a-4ab7-bfb5-d96b73331a29.filesusr.com/ugd/b58d21_d27323beb23e49ad94a2ee9bac709720.pdf?index=true
- https://c98ef715-888c-40fa-948d-05e409150a10.filesusr.com/ugd/681527_5594e0ad9147488dad0ece52c0b38a6a.pdf?index=true
- https://a6933271-3e26-4cef-b40f-ac46484b5ad4.filesusr.com/ugd/e2c6c1_3d2b0771b71a4fc79f5c9f3711b20c8f.pdf?index=true
- https://bff600fb-c2e9-419e-a356-269ed3d78a19.filesusr.com/ugd/8a4248_92012e4ac50f443a90572fa95a61d6c0.pdf?index=true
- https://9c4f837b-3c5e-4cb4-960b-1aaded256e04.filesusr.com/ugd/ac8c68_5a2cd6093bca4c93adcd8bee52a07e9c.pdf?index=true
- https://73e66511-3033-452d-ab2e-8d70c9b0eaa1.filesusr.com/ugd/e948c1_96319e4a18cb44c89b4b3f9de0fc0bcb.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.me
- 55cd38ab-cc2f-4ab8-9e9a-181ad073084b.filesusr.com
- 614eeb68-2662-4969-9b84-06020f42efdc.filesusr.com
- 18b3e02f-9920-4307-901c-02899b80f5dd.filesusr.com
- 357c084e-71e6-40af-8b83-297a8dc89711.filesusr.com
- 4ef574a2-fdbf-4519-8610-8677e257b14a.filesusr.com
- cdn.shopify.com
- 13fe947d-383a-4ab7-bfb5-d96b73331a29.filesusr.com
- c98ef715-888c-40fa-948d-05e409150a10.filesusr.com
- a6933271-3e26-4cef-b40f-ac46484b5ad4.filesusr.com
- bff600fb-c2e9-419e-a356-269ed3d78a19.filesusr.com
- 9c4f837b-3c5e-4cb4-960b-1aaded256e04.filesusr.com
- 73e66511-3033-452d-ab2e-8d70c9b0eaa1.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report