MALICIOUS — 33ab24_d0bbaa8dd94149eca34f55d90ad67af0.pdf
MALICIOUS — 33ab24_d0bbaa8dd94149eca34f55d90ad67af0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
6ce49021f926fe0ed5988390bde5e3b3c51e34b328909b029377f1e4e9814f0f - SHA-1:
adc261ab1a45db81f34a1b1f02d2c86f3c6083ab - MD5:
66ad254ef4e823dbebcfbc6b34f54d55 - ssdeep:
768:0gGzpDRFIqHab5fgxD++U1hsiRaXl2nNyRQuAxdAD4fFL:BGF9FoqDAdRaXggCuAxRfFL - TLSH:
T19B319CF350A3ED8C7A8AAB13ADA710A69049C68C7133E76118DC772CD87C5FDAD11861 - Submitted as: 33ab24_d0bbaa8dd94149eca34f55d90ad67af0.pdf
- File type: pdf · Size: 40281 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.club/wix?keyword=zombie+castaways+mod+apk, http://files.sneakerbots4all.com/uploads/1/3/0/7/130776103/fcc3875951065.pdf, http://files.marieleneudecker.co.uk/uploads/1/3/1/4/131407281/fimof.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/wix?keyword=zombie+castaways+mod+apk
- http://files.sneakerbots4all.com/uploads/1/3/0/7/130776103/fcc3875951065.pdf
- http://files.marieleneudecker.co.uk/uploads/1/3/1/4/131407281/fimof.pdf
- http://nipazok.floraelmore.com/uploads/1/3/1/8/131856161/6f4db4b8b7.pdf
- http://ginutuga.contributewater.com/uploads/1/3/1/3/131384260/6497992.pdf
- https://cdn.shopify.com/s/files/1/0430/6268/9946/files/acme_thread_dimensions.pdf
- https://cdn.shopify.com/s/files/1/0428/8364/5599/files/90820824986.pdf
- https://cdn.shopify.com/s/files/1/0436/9124/5733/files/sugixavagoviveboxilotofoz.pdf
- https://cdn.shopify.com/s/files/1/0432/5412/0606/files/52260994093.pdf
- https://cdn.shopify.com/s/files/1/0435/9235/1907/files/17895858581.pdf
- https://0f713d39-b414-4eff-bedf-f69db2a7909b.filesusr.com/ugd/c83fdb_07eca63a99cb49b3845ca2a1cfc06e6f.pdf?index=true
- https://b4808514-6dd3-41cd-a125-039f28d0f7da.filesusr.com/ugd/685707_e29c7a016eb44fcbbdfa8d0e75042cbc.pdf?index=true
- https://619a9b77-79a3-4b37-824d-efc722fef763.filesusr.com/ugd/8da65f_8ca9883c3e694dcaaa1c2d3d0e360901.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.club
- files.sneakerbots4all.com
- files.marieleneudecker.co.uk
- nipazok.floraelmore.com
- ginutuga.contributewater.com
- cdn.shopify.com
- 0f713d39-b414-4eff-bedf-f69db2a7909b.filesusr.com
- b4808514-6dd3-41cd-a125-039f28d0f7da.filesusr.com
- 619a9b77-79a3-4b37-824d-efc722fef763.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report