MALICIOUS — 84215131808.pdf
MALICIOUS — 84215131808.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
791f9615296e0f52eff3203998be14754fb94168d82b0e74a142a039aa3706d9 - SHA-1:
f7782d2582213525b3072f53f06796875fbc4e12 - MD5:
29ef81884801ebf22b32ac23793af2d3 - ssdeep:
768:ggGzpD9yKTtMaEpb8Xizm3Y6UXI5cn78JNnIw:tGFBrn2wXa6UXwg7kNnIw - TLSH:
T11C319EF320DBED8C3A8B9B03ADA61155648AC688A133A76005DC733DD5BC6BE9F50850 - Submitted as: 84215131808.pdf
- File type: pdf · Size: 42892 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ggtraff.ru/strik?keyword=aquaculture+magazine+pdf, http://files.nativetales.com/uploads/1/3/1/4/131407629/widatufu.pdf, http://tigobemow.inherownrite.com/uploads/1/3/1/8/131871655/tatadavomit-fuwopoxape-fojetarolufifet-bonojunegatizop.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=aquaculture+magazine+pdf
- http://files.nativetales.com/uploads/1/3/1/4/131407629/widatufu.pdf
- http://tigobemow.inherownrite.com/uploads/1/3/1/8/131871655/tatadavomit-fuwopoxape-fojetarolufifet-bonojunegatizop.pdf
- http://bedani.ecommplish.com/uploads/1/3/2/3/132302978/kupamisofefap.pdf
- http://files.el-mastaba.org/uploads/1/3/0/8/130874540/c7b6e.pdf
- http://files.lukesconcrete.com/uploads/1/3/1/3/131379743/7326521.pdf
- http://files.brownwoodlake.com/uploads/1/3/0/7/130776089/xufowogemaxebib.pdf
- http://wovizodon.victoriaheathart.com/uploads/1/3/1/3/131378960/sonadurotesameki.pdf
- http://libonowa.ncelssp.com/uploads/1/3/1/3/131380594/noromoputafemuxutito.pdf
- http://bebiwo.brightonandhovehypnobirthing.co.uk/uploads/1/3/1/8/131856072/1141110.pdf
- https://uploads.strikinglycdn.com/files/31632ec0-d0b2-4088-aa74-f15318742dae/rovilavuxelobafolunupives.pdf
- https://uploads.strikinglycdn.com/files/19f63737-3327-46ad-b38e-5d7b4b3d283d/gilumifevijir.pdf
- https://uploads.strikinglycdn.com/files/6731f7dd-583d-4771-b6b6-e000685526b8/didunanaxemavepevunip.pdf
- https://uploads.strikinglycdn.com/files/728d92b3-3959-4194-97e6-5e8771ccced1/45164984781.pdf
- https://uploads.strikinglycdn.com/files/acd84499-6589-4b63-a301-1a4f8517b9de/lizafexabarev.pdf
- https://site-1036699.mozfiles.com/files/1036699/86409646955.pdf
- https://site-1036753.mozfiles.com/files/1036753/4932660152.pdf
- https://site-1036929.mozfiles.com/files/1036929/11947610436.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- files.nativetales.com
- tigobemow.inherownrite.com
- bedani.ecommplish.com
- files.el-mastaba.org
- files.lukesconcrete.com
- files.brownwoodlake.com
- wovizodon.victoriaheathart.com
- libonowa.ncelssp.com
- bebiwo.brightonandhovehypnobirthing.co.uk
- uploads.strikinglycdn.com
- site-1036699.mozfiles.com
- site-1036753.mozfiles.com
- site-1036929.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report