MALICIOUS — 6f53d7_a04333f93874452b80f7a6ce7b85edd3.pdf
MALICIOUS — 6f53d7_a04333f93874452b80f7a6ce7b85edd3.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
777296d34cd1c7dd1535519afca7f7dfb2610c75aee405cb5e5a246db58c6252 - SHA-1:
ba4b9aca6e49a17f2930b6d873304c08dbbcef4e - MD5:
efcb5f2213b63d91cdc8d7bde72694b9 - ssdeep:
768:7gGzpD+6y9g4FbvS8ahUhn1FBhlOqxgUb0egKDwyF0OtUB:EGF6/vh99VTHgkwya/B - TLSH:
T181319DF751ABDC8C3A87CB23A897215E6445D68D7023A76509986B2CC4BC2FDAF10931 - Submitted as: 6f53d7_a04333f93874452b80f7a6ce7b85edd3.pdf
- File type: pdf · Size: 41224 bytes
- Verdict: malicious (88/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.PDF.Agent.gen (rule
HEUR:Trojan.PDF.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.link/wix?keyword=mitosis+versus+meiosis+worksheet+17+answer+key, https://18b060b0-a1cc-4c19-adc8-0b1e48b6cb85.filesusr.com/ugd/665c20_45870d922713472bad4157e1594de84b.pdf?index=true, https://5b669096-fb5a-4c24-961e-06b6be93547c.filesusr.com/ugd/9904c2_2c430b493bbf4743bee71aab67c06748.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/wix?keyword=mitosis+versus+meiosis+worksheet+17+answer+key
- https://18b060b0-a1cc-4c19-adc8-0b1e48b6cb85.filesusr.com/ugd/665c20_45870d922713472bad4157e1594de84b.pdf?index=true
- https://5b669096-fb5a-4c24-961e-06b6be93547c.filesusr.com/ugd/9904c2_2c430b493bbf4743bee71aab67c06748.pdf?index=true
- https://8d94b0a8-b82f-42e1-b594-d2315a26aa50.filesusr.com/ugd/29c71c_49d5a9c3338d4b62ae9720d16424fc66.pdf?index=true
- https://c16f02a3-0324-495b-ab0a-16c06f8a9c23.filesusr.com/ugd/4e977a_069886cfd2624007a3a1776d0c9ff59a.pdf?index=true
- https://73b075f2-0e70-4cc2-a1a6-701f95c5073a.filesusr.com/ugd/44b221_7dd856a3bdc149cb8d199c16e540dd00.pdf?index=true
- http://joburol.mimifdn.org/uploads/1/3/1/3/131383652/18e5aae6fb5.pdf
- http://tabosile.cobbuildingwithmaya.com/uploads/1/3/0/7/130776854/2084329.pdf
- http://wumolef.khhairkare.com/uploads/1/3/1/3/131381352/7459621.pdf
- http://runavun.growth-ministries.org/uploads/1/3/2/7/132712237/d0ac9dd3.pdf
- http://kunuruku.breedengallery.com/uploads/1/3/2/7/132740829/7213947.pdf
- https://5f258df2-b69b-441f-a54b-c8927919d9a1.filesusr.com/ugd/1acd69_0464ef6cd5fb4bbc8cf88674dfd83eb4.pdf?index=true
- https://14db3ad9-1995-4a17-abab-0d0e80c821ac.filesusr.com/ugd/d5cf39_95d11886070040b0b450ce8cb985dc83.pdf?index=true
- https://cdn.shopify.com/s/files/1/0435/9775/8622/files/32652237043.pdf
- https://cdn.shopify.com/s/files/1/0440/6090/1526/files/terapia_de_pareja_puerto_rico_cayey.pdf
- https://cdn.shopify.com/s/files/1/0433/7742/6588/files/gukarutemikufi.pdf
- https://cdn.shopify.com/s/files/1/0433/8122/7672/files/63182200470.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.link
- 18b060b0-a1cc-4c19-adc8-0b1e48b6cb85.filesusr.com
- 5b669096-fb5a-4c24-961e-06b6be93547c.filesusr.com
- 8d94b0a8-b82f-42e1-b594-d2315a26aa50.filesusr.com
- c16f02a3-0324-495b-ab0a-16c06f8a9c23.filesusr.com
- 73b075f2-0e70-4cc2-a1a6-701f95c5073a.filesusr.com
- joburol.mimifdn.org
- tabosile.cobbuildingwithmaya.com
- wumolef.khhairkare.com
- runavun.growth-ministries.org
- kunuruku.breedengallery.com
- 5f258df2-b69b-441f-a54b-c8927919d9a1.filesusr.com
- 14db3ad9-1995-4a17-abab-0d0e80c821ac.filesusr.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report