MALICIOUS — 163759_3eda1c072a7e4b8e90adb32330032a40.pdf
MALICIOUS — 163759_3eda1c072a7e4b8e90adb32330032a40.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
60bd24071115d9fb512fe2dd9a894d806aacba159ea4338d1768bf6c3357946c - SHA-1:
a8d729f63aac7a68fca7ea27450c86f234da2b48 - MD5:
59583d5c03f4448b534c1a99e9416cd4 - ssdeep:
768:wbgGzpDScemx14FHmsnXFbjBvIJ0ANFEHvhQoA9Pn9di7lu6z4tH:wkGFxyXFbVjkaHvyL9v9di7E6z4H - TLSH:
T1D832AFF34067FC8C6B8A9F479AA6145AA542D789B13307B418C8776CD87C7FDAE00650 - Submitted as: 163759_3eda1c072a7e4b8e90adb32330032a40.pdf
- File type: pdf · Size: 46801 bytes
- Verdict: malicious (88/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.cc/wix?keyword=chapter+15+sound+study+guide+answers+glencoe, http://files.naturalisllc.net/uploads/1/3/1/8/131872238/0063df60f2ef7.pdf, http://zuxumomup.diplomainprofessionalstudies.com/uploads/1/3/2/6/132680981/zoleve.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/wix?keyword=chapter+15+sound+study+guide+answers+glencoe
- http://files.naturalisllc.net/uploads/1/3/1/8/131872238/0063df60f2ef7.pdf
- http://zuxumomup.diplomainprofessionalstudies.com/uploads/1/3/2/6/132680981/zoleve.pdf
- http://saruleji.thethirtyfirst.org/uploads/1/3/0/7/130739980/jafiwimex-mapowuza-bodakuxu.pdf
- http://tijadep.850plants.com/uploads/1/3/0/7/130739344/gamiteduzalare-nodejezefago-rewuvej.pdf
- http://files.tlghk.org/uploads/1/3/1/6/131637679/xiwomojuxokiwurute.pdf
- http://files.montealea.org/uploads/1/3/1/6/131637763/fuzivomabetunewuxof.pdf
- http://guxaxeb.maestrodonappert.com/uploads/1/3/2/3/132303354/kajakozokezan.pdf
- https://296eb524-fe53-49bd-af63-39337a5460f0.filesusr.com/ugd/7dd30d_0169cdd873f347978ad0bd126d65ab2e.pdf?index=true
- https://834991de-787d-4161-aefb-c7dcde204c96.filesusr.com/ugd/f09a9d_b54fda49e0bf4fd3a277a579bef394be.pdf?index=true
- https://266090ff-a053-42e4-a15a-d83395ba3d3f.filesusr.com/ugd/fe83c3_b9965e83d790445fba30e9d45a5cf388.pdf?index=true
- https://4ec6b28b-d270-4e29-b42f-69f0e0ff1170.filesusr.com/ugd/9117e0_e24bbc98af414d119945f85e5fc94071.pdf?index=true
- https://cdn.shopify.com/s/files/1/0431/9277/8916/files/android_pptp_vpn_source_code.pdf
- https://cdn.shopify.com/s/files/1/0441/3338/4344/files/917668661.pdf
- https://cdn.shopify.com/s/files/1/0434/1802/6142/files/56725735325.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.cc
- files.naturalisllc.net
- zuxumomup.diplomainprofessionalstudies.com
- saruleji.thethirtyfirst.org
- tijadep.850plants.com
- files.tlghk.org
- files.montealea.org
- guxaxeb.maestrodonappert.com
- 296eb524-fe53-49bd-af63-39337a5460f0.filesusr.com
- 834991de-787d-4161-aefb-c7dcde204c96.filesusr.com
- 266090ff-a053-42e4-a15a-d83395ba3d3f.filesusr.com
- 4ec6b28b-d270-4e29-b42f-69f0e0ff1170.filesusr.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report