MALICIOUS — 008e52_1cda9c7966134c26a5b46b5262c5ed0b.pdf
MALICIOUS — 008e52_1cda9c7966134c26a5b46b5262c5ed0b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
630fd46c915b62272bcd8deba9f558a695743dd0105c005aa56fd6412303a341 - SHA-1:
499d986eb3a7bda15c132ca6168dae66368c5651 - MD5:
89ace103e7ac7a831a922cf3ce2feb95 - ssdeep:
1536:YGFdfGf+DU9A5Xy4fbFbzReAY0U4WlEvSUpU:1FdeUeAJZhbcAYzF8Sh - TLSH:
T12133BFF311A7DD88B6CB9F03ADA7151C614AC78D323396A045D87B2CC4BC6ED6E40A60 - Submitted as: 008e52_1cda9c7966134c26a5b46b5262c5ed0b.pdf
- File type: pdf · Size: 49324 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=boom+beach+guide+pdf, http://bomewib.makersri.com/uploads/1/3/0/7/130740514/wogiza.pdf, http://sewimomir.oetprep.com/uploads/1/3/1/4/131406592/lujikizad-pavesonuji-vuvepamojupu-reronofoxom.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/wix?keyword=boom+beach+guide+pdf
- http://bomewib.makersri.com/uploads/1/3/0/7/130740514/wogiza.pdf
- http://sewimomir.oetprep.com/uploads/1/3/1/4/131406592/lujikizad-pavesonuji-vuvepamojupu-reronofoxom.pdf
- http://gelotoge.proplayhockey.ca/uploads/1/3/2/8/132814342/lepadag.pdf
- https://cdn.shopify.com/s/files/1/0434/2589/0469/files/sajolovivigolul.pdf
- https://e56f7a07-2b15-4f14-9403-882140353a03.filesusr.com/ugd/c12414_fce2c5d2e0b8461e902e844617bbd5a4.pdf?index=true
- https://dd8ace19-4508-4976-8d5e-657535bf4200.filesusr.com/ugd/5de1df_f5a9713149d9441a8de4e101c4b3bcd7.pdf?index=true
- https://52788157-8e60-451c-8712-e90657820c7b.filesusr.com/ugd/e3ed1f_bbff4ed6a2f14685a4800b683c920f19.pdf?index=true
- https://0932b980-6958-4029-8fb6-c804db9379ae.filesusr.com/ugd/d38238_811174818f1e47f4b7f1d88b5a20a452.pdf?index=true
- https://58330a1c-6363-4e61-9d74-a9549eecf02f.filesusr.com/ugd/daca0d_7c0ce997a401413f988d6afbbc54e7c3.pdf?index=true
- https://40146508-1a90-4418-831a-bcd961408659.filesusr.com/ugd/6cf392_5d92f7001fef4e8fa8958a016afc9d4d.pdf?index=true
- https://cc23b9e6-2f4f-4c61-bebb-9260807f52c1.filesusr.com/ugd/7a359d_354f82ea900f4aeb94852e026aa4148a.pdf?index=true
- https://b9e4b5b1-1fb2-491a-bf30-b242949f85be.filesusr.com/ugd/65e777_dc7e7bf4553f4a17ab1d3aecabeb3396.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- bomewib.makersri.com
- sewimomir.oetprep.com
- gelotoge.proplayhockey.ca
- cdn.shopify.com
- e56f7a07-2b15-4f14-9403-882140353a03.filesusr.com
- dd8ace19-4508-4976-8d5e-657535bf4200.filesusr.com
- 52788157-8e60-451c-8712-e90657820c7b.filesusr.com
- 0932b980-6958-4029-8fb6-c804db9379ae.filesusr.com
- 58330a1c-6363-4e61-9d74-a9549eecf02f.filesusr.com
- 40146508-1a90-4418-831a-bcd961408659.filesusr.com
- cc23b9e6-2f4f-4c61-bebb-9260807f52c1.filesusr.com
- b9e4b5b1-1fb2-491a-bf30-b242949f85be.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report