MALICIOUS — 162fe6_2562f701331a48708d0003ff904010dd.pdf
MALICIOUS — 162fe6_2562f701331a48708d0003ff904010dd.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
7ab813f3d4f58acb3ce3ae821b99d4f5330122491506f6d477a19f0a70d16084 - SHA-1:
abc01738ce562f7baac356fac3aac243edc588d7 - MD5:
5f8ef45685adb79095c268e626e08d4d - ssdeep:
1536:YGFlH4lyj3K9BR3cSvLvqvJ8ua6SJofEz:1FlH4gja9MpvJZhSJ7 - TLSH:
T1A235C0F340ABDC8C7A8A6B13E9E6118D7159D7CDB03A96706499767CC0BC6ED6F00620 - Submitted as: 162fe6_2562f701331a48708d0003ff904010dd.pdf
- File type: pdf · Size: 60504 bytes
- Verdict: malicious (88/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=la+luna+sangre+september+19+2019, https://a74e7e29-9c3c-4d10-882c-87356c630731.filesusr.com/ugd/5bb01c_930112759c6943a59f55245cd3cf8a41.pdf?index=true, https://8bad8734-bbae-453c-85ea-d094766a75c7.filesusr.com/ugd/bcc0e4_4efc72bcc52a458a92aef05a3539a595.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/wix?keyword=la+luna+sangre+september+19+2019
- https://a74e7e29-9c3c-4d10-882c-87356c630731.filesusr.com/ugd/5bb01c_930112759c6943a59f55245cd3cf8a41.pdf?index=true
- https://8bad8734-bbae-453c-85ea-d094766a75c7.filesusr.com/ugd/bcc0e4_4efc72bcc52a458a92aef05a3539a595.pdf?index=true
- https://9c6b1b41-885f-44e6-a3e5-74ba6043cef0.filesusr.com/ugd/c5d40f_84b324f982884dc1953285931301d628.pdf?index=true
- https://76d5f580-cdb6-4bbd-a933-85bf13f036c2.filesusr.com/ugd/d43733_f9ecfd7b2efd4965afd465ceef707463.pdf?index=true
- https://5cf32fc1-4847-4801-8541-f718b8fc29e2.filesusr.com/ugd/3be48b_57c46333dfc147fe90a8be50efd22718.pdf?index=true
- http://vopofaket.penultimatephotos.com/uploads/1/3/0/9/130969264/kuxijapufidugoj-jomawizakog-zejejegekizudi-setobu.pdf
- http://files.edinboromckeanvfwpost740.com/uploads/1/3/0/7/130739835/978846.pdf
- http://files.heavenlypoodlesanddodles.com/uploads/1/3/1/4/131453574/9870458.pdf
- http://fivig.virgilmathes.com/uploads/1/3/0/7/130739001/1466210.pdf
- http://savozim.templargames.com/uploads/1/3/1/6/131606479/612785.pdf
- http://files.marisareneephoto.com/uploads/1/3/1/3/131380786/xodavuvikuje.pdf
- https://138ac612-ae68-4673-81b5-f9e8fbf9966d.filesusr.com/ugd/33ab24_16aa0af066ab412496c9bb42f6a23da0.pdf?index=true
- https://027ea805-1c42-41ea-ac16-5c156fe89b2c.filesusr.com/ugd/cc3ca9_df41538f760b481997f2edc4298421c1.pdf?index=true
- https://5f7601d2-faad-4bac-97d4-0f56785d0cb2.filesusr.com/ugd/2994dd_86ec2040518f450f9eed38cd7b52893f.pdf?index=true
- https://f50415fd-1bed-43ab-8fa2-73165d828dc3.filesusr.com/ugd/b148e5_118f9e78462a4a8ab9670e8333d5017b.pdf?index=true
- https://a89a02ec-b820-4faf-9e9b-3db5d0b75d97.filesusr.com/ugd/b148e5_bbc681a3de5d4ae0a766add6173dc51c.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- a74e7e29-9c3c-4d10-882c-87356c630731.filesusr.com
- 8bad8734-bbae-453c-85ea-d094766a75c7.filesusr.com
- 9c6b1b41-885f-44e6-a3e5-74ba6043cef0.filesusr.com
- 76d5f580-cdb6-4bbd-a933-85bf13f036c2.filesusr.com
- 5cf32fc1-4847-4801-8541-f718b8fc29e2.filesusr.com
- vopofaket.penultimatephotos.com
- files.edinboromckeanvfwpost740.com
- files.heavenlypoodlesanddodles.com
- fivig.virgilmathes.com
- savozim.templargames.com
- files.marisareneephoto.com
- 138ac612-ae68-4673-81b5-f9e8fbf9966d.filesusr.com
- 027ea805-1c42-41ea-ac16-5c156fe89b2c.filesusr.com
- 5f7601d2-faad-4bac-97d4-0f56785d0cb2.filesusr.com
- f50415fd-1bed-43ab-8fa2-73165d828dc3.filesusr.com
- a89a02ec-b820-4faf-9e9b-3db5d0b75d97.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report