MALICIOUS — 9904c2_936583c332834d788a2040ac5cf80572.pdf
MALICIOUS — 9904c2_936583c332834d788a2040ac5cf80572.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
59d89c6570949475557d622a4a92b48692a3119319c275925243960c281c2859 - SHA-1:
8c5706ae51a287c5b63d21aec6cd849f276a650c - MD5:
c9bba89ed24df72b3f5e6064993d6037 - ssdeep:
768:BgGzpDycmZ43vduML7zmYyQbeGPs/KcsATQJD+:yGF28uMPbeGPgK5ATQJD+ - TLSH:
T165319EF75097DC8C7ACE5F53AEE6115A6186DA8D6023A6B4098C3B3CC47C3ED6E10A11 - Submitted as: 9904c2_936583c332834d788a2040ac5cf80572.pdf
- File type: pdf · Size: 39960 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=solving+systems+by+substitution+worksheet+pdf, http://subedojip.ewsrl.com/uploads/1/3/1/0/131070171/8dcd4947d634.pdf, http://bepomi.graphictechgroup.com/uploads/1/3/0/7/130775320/02d896ab.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/wix?keyword=solving+systems+by+substitution+worksheet+pdf
- http://subedojip.ewsrl.com/uploads/1/3/1/0/131070171/8dcd4947d634.pdf
- http://bepomi.graphictechgroup.com/uploads/1/3/0/7/130775320/02d896ab.pdf
- http://files.charlottechiphi.com/uploads/1/3/2/7/132740586/ninitu.pdf
- http://jerutimem.beboskonacoffee.com/uploads/1/3/0/9/130969723/rodanefexoj-dalomemop.pdf
- http://files.garden-of-luminaria.com/uploads/1/3/1/8/131856492/rurakugokijafe.pdf
- https://a07e99dd-f70e-4608-8bb3-00522da1158b.filesusr.com/ugd/610d21_b0bf181289374df5b36f23596b9b5271.pdf?index=true
- https://91d86810-6c0e-4bd8-92a7-bc87c2d1c2d3.filesusr.com/ugd/65b209_4b74c10e00674ab9af89e58d202e72d0.pdf?index=true
- https://26055df2-d2e7-4d13-b17a-2c6b534548bb.filesusr.com/ugd/bcc0e4_7e2ba91adb3e4629b0cdb1c98fe2953d.pdf?index=true
- https://3fb00cab-3103-492b-ba05-776a71ae3f94.filesusr.com/ugd/8e7730_828d6836a8db4307b94a5184ec75cf7a.pdf?index=true
- https://26fdc8cc-094c-436f-930f-211c93324804.filesusr.com/ugd/938c70_a09db7811fc54066b4e4a1cc73cbb139.pdf?index=true
- https://20552341-690e-40dd-9220-af6265b96646.filesusr.com/ugd/162fe6_6612a1f5372043ee98bbca8f750578ff.pdf?index=true
- https://01ba4484-fa54-4d8e-83eb-74aef0dae94d.filesusr.com/ugd/a4ea6c_3286253cbf8a4eb7aff2986e936435fe.pdf?index=true
- https://3b74e6f0-e841-4984-a5dc-caac1ff2b142.filesusr.com/ugd/9058e5_a10a21681b13460fb879e70dd7a9ff7d.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- subedojip.ewsrl.com
- bepomi.graphictechgroup.com
- files.charlottechiphi.com
- jerutimem.beboskonacoffee.com
- files.garden-of-luminaria.com
- a07e99dd-f70e-4608-8bb3-00522da1158b.filesusr.com
- 91d86810-6c0e-4bd8-92a7-bc87c2d1c2d3.filesusr.com
- 26055df2-d2e7-4d13-b17a-2c6b534548bb.filesusr.com
- 3fb00cab-3103-492b-ba05-776a71ae3f94.filesusr.com
- 26fdc8cc-094c-436f-930f-211c93324804.filesusr.com
- 20552341-690e-40dd-9220-af6265b96646.filesusr.com
- 01ba4484-fa54-4d8e-83eb-74aef0dae94d.filesusr.com
- 3b74e6f0-e841-4984-a5dc-caac1ff2b142.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report