MALICIOUS — c1de29_1d65820267c240c9a932b7ea26532d38.pdf
MALICIOUS — c1de29_1d65820267c240c9a932b7ea26532d38.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (78/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
7609e45ad434d047d6c5f69a933667a620fde1d7d3561efe130e9596144fdbc4 - SHA-1:
f3811ff8e5ff41b3ccd3dea6c5f09a65f9fb4727 - MD5:
3495bc65c4d0d13eb2eaa0b093d33d89 - ssdeep:
1536:ZGFBejWa6+WTnRJ3M8PDiVumTxZKFe1pjDn8Dy/fecV0oBS7tHWSHpZAIfUk:sFBLa6+WDRFbiMAKFcpjD8Dyec2ow7tv - TLSH:
T1CA37AEF31196ED8C36C6EB0778B62054614BDB8C3233AA944489BBBCC57C6BD5E10B51 - Submitted as: c1de29_1d65820267c240c9a932b7ea26532d38.pdf
- File type: pdf · Size: 74085 bytes
- Verdict: malicious (78/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 78/100 is the fusion of 5 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=what+does+little+miss+muffet+mean, https://f09ab041-2525-400c-b78f-da62fa1d03ce.filesusr.com/ugd/d4a9d6_0a9641f6a9074f549d2003421c4d2da1.pdf?index=true, https://ac3e887a-d8c7-4a55-9adf-5b6eb4d05d5e.filesusr.com/ugd/edb4a7_ed067165fe884384aba3d7abbc330478.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/wix?keyword=what+does+little+miss+muffet+mean
- https://f09ab041-2525-400c-b78f-da62fa1d03ce.filesusr.com/ugd/d4a9d6_0a9641f6a9074f549d2003421c4d2da1.pdf?index=true
- https://ac3e887a-d8c7-4a55-9adf-5b6eb4d05d5e.filesusr.com/ugd/edb4a7_ed067165fe884384aba3d7abbc330478.pdf?index=true
- https://064c4c64-352d-4f3f-9a02-ee782fec9b4e.filesusr.com/ugd/405339_15d91cc5026848faafe613ef7997309b.pdf?index=true
- https://2ae7d11b-910d-45af-9267-aaa0fe99ed8a.filesusr.com/ugd/4725f1_77ee3cafe7074a22acadc3bf579e9936.pdf?index=true
- https://154c2848-fda4-4554-9897-5b2054a172bf.filesusr.com/ugd/d6af85_fc13a69092fe43ad9ca1c65305238b4b.pdf?index=true
- https://cdn.shopify.com/s/files/1/0431/7564/1247/files/46269947490.pdf
- https://cdn.shopify.com/s/files/1/0437/8741/9805/files/zolesokivubar.pdf
- https://c9abc0cd-d179-4c2b-9bb5-4bdc16e9dcdc.filesusr.com/ugd/8bf3fc_e1fd56a2d43e4c49acc8c4942b995184.pdf?index=true
- https://f886fb83-396c-43d4-9dff-6cbfeb9674ba.filesusr.com/ugd/26481d_be9f9321e68a40fa8137f0286ba9fd5b.pdf?index=true
- https://ca2fdbb8-7063-401d-94b9-eac1811bdd4c.filesusr.com/ugd/f6336d_dcb1a462c2da40a48bbc28fa7e63aab2.pdf?index=true
- https://abce3120-9ad9-4d08-9680-0c0da20dbabc.filesusr.com/ugd/f6336d_74a4e517fddb4f0ba9195c691141a825.pdf?index=true
- https://41ab8eda-d43e-49c9-b489-63b7e6414283.filesusr.com/ugd/49f5ef_b3fdef0b95a94a51b58b7db7053c136c.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- f09ab041-2525-400c-b78f-da62fa1d03ce.filesusr.com
- ac3e887a-d8c7-4a55-9adf-5b6eb4d05d5e.filesusr.com
- 064c4c64-352d-4f3f-9a02-ee782fec9b4e.filesusr.com
- 2ae7d11b-910d-45af-9267-aaa0fe99ed8a.filesusr.com
- 154c2848-fda4-4554-9897-5b2054a172bf.filesusr.com
- cdn.shopify.com
- c9abc0cd-d179-4c2b-9bb5-4bdc16e9dcdc.filesusr.com
- f886fb83-396c-43d4-9dff-6cbfeb9674ba.filesusr.com
- ca2fdbb8-7063-401d-94b9-eac1811bdd4c.filesusr.com
- abce3120-9ad9-4d08-9680-0c0da20dbabc.filesusr.com
- 41ab8eda-d43e-49c9-b489-63b7e6414283.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report