MALICIOUS — 120874_9f62fcf01f5948eaba6c4251e2bf71fa.pdf
MALICIOUS — 120874_9f62fcf01f5948eaba6c4251e2bf71fa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
5ce7441eac2f234bcee392e845b98d02a8ec09f0f7c57b8cec2b25e2200cd2d3 - SHA-1:
93eed4e9f37211d4d28c3bd357cfde0a96f1bd2a - MD5:
6c5195022ce06af714b5327c66bf33a4 - ssdeep:
768:GgGzpDS2W9zZJAAv5wlw6aV8XFXabrxbVuUkXLf+XL4N9zjtH:TGFWP9LAYwyTVoE/zuNYy9zZH - TLSH:
T19C318DF300A7ED4C7B9A9B036DA6106D508AC6496133D66845D8BB7CC4BC2BDBE90531 - Submitted as: 120874_9f62fcf01f5948eaba6c4251e2bf71fa.pdf
- File type: pdf · Size: 42530 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.me/wix?keyword=persona+3+boss+level+guide, https://1b534c98-e277-4b02-9048-d943de985a90.filesusr.com/ugd/e54fc7_693ae91c6fdd4eb4ad13a5958d5585f2.pdf?index=true, https://fec73f6d-4505-40a4-b491-b4a84ae0f3bb.filesusr.com/ugd/6a7407_14b6691a0028468e8ee252f950acb60e.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/wix?keyword=persona+3+boss+level+guide
- https://1b534c98-e277-4b02-9048-d943de985a90.filesusr.com/ugd/e54fc7_693ae91c6fdd4eb4ad13a5958d5585f2.pdf?index=true
- https://fec73f6d-4505-40a4-b491-b4a84ae0f3bb.filesusr.com/ugd/6a7407_14b6691a0028468e8ee252f950acb60e.pdf?index=true
- https://6f2f9bc9-a73c-4689-a869-ba75c9dc546a.filesusr.com/ugd/bba345_b7396205c2d649ecbeddb3d13ccdfa99.pdf?index=true
- http://files.ourhousecallvet.net/uploads/1/3/1/8/131857071/semosi-kimixasobal-baxokuw.pdf
- http://mewaxe.ourlittlebitranch.com/uploads/1/3/1/3/131398404/2871649.pdf
- http://files.timelesshealthseattle.com/uploads/1/3/1/0/131070144/de9b45926d46.pdf
- http://files.homebirthsupply.com/uploads/1/3/0/7/130775471/6452645.pdf
- http://buxitisow.stmaryslibrary.org/uploads/1/3/0/8/130813714/wotakatanosaze.pdf
- http://files.linkyscloset.com/uploads/1/3/1/4/131454771/099dc7d8de50244.pdf
- https://405de307-33be-44d0-bf13-bb2d36e714c8.filesusr.com/ugd/dcf9ad_a47cfeffa96d4cefafd1f5d3c004ee09.pdf?index=true
- https://dca47d51-590a-426c-846c-6212a50484be.filesusr.com/ugd/8ce377_83b7f1ebd5b8497c88eee5d746452021.pdf?index=true
- https://9269322b-fc9f-4e05-ac04-880ba55b734f.filesusr.com/ugd/d2751c_527db70e33d74f83af133dc38e3b8c7f.pdf?index=true
- https://972ec1eb-cd0a-4ba4-b5be-6c13c98fd7d8.filesusr.com/ugd/f95141_7f44d006f2414604a02b360d73c060bf.pdf?index=true
- https://0e0f5863-8a77-44df-a4b2-9e58ff747e08.filesusr.com/ugd/3b6424_dbf8c3b533d64ab1b8defef36b5456e0.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.me
- 1b534c98-e277-4b02-9048-d943de985a90.filesusr.com
- fec73f6d-4505-40a4-b491-b4a84ae0f3bb.filesusr.com
- 6f2f9bc9-a73c-4689-a869-ba75c9dc546a.filesusr.com
- files.ourhousecallvet.net
- mewaxe.ourlittlebitranch.com
- files.timelesshealthseattle.com
- files.homebirthsupply.com
- buxitisow.stmaryslibrary.org
- files.linkyscloset.com
- 405de307-33be-44d0-bf13-bb2d36e714c8.filesusr.com
- dca47d51-590a-426c-846c-6212a50484be.filesusr.com
- 9269322b-fc9f-4e05-ac04-880ba55b734f.filesusr.com
- 972ec1eb-cd0a-4ba4-b5be-6c13c98fd7d8.filesusr.com
- 0e0f5863-8a77-44df-a4b2-9e58ff747e08.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report