MALICIOUS — dcf9ad_02b99cc910254a08b70f02757f093c48.pdf
MALICIOUS — dcf9ad_02b99cc910254a08b70f02757f093c48.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
83b2769df78a80b4b5d9aeace994a4a6d1cf3cbce3ab59597aab0e7e0f91bf94 - SHA-1:
8ee2cfe30ec2b8c27441529243a5ca0ddcfd9cc0 - MD5:
ae397fee16ff01a680ab3dd578434191 - ssdeep:
768:DgGzpD14AleFZG6xFov/XfD8WaSoQMtiHh1a1DieNvx7noS9OH:8GFBQfovvfYEoFwB1Qp5noS9OH - TLSH:
T1DA319EF31047EE8C3ACB5B07AEAA049D6146D64E6133A62015DD7B3CC4BC6FD6E14960 - Submitted as: dcf9ad_02b99cc910254a08b70f02757f093c48.pdf
- File type: pdf · Size: 43145 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=pandora+plus+apk, https://cdn.shopify.com/s/files/1/0438/5095/6960/files/winchester_1897_for_sale.pdf, https://cdn.shopify.com/s/files/1/0430/6753/9623/files/32729379467.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/wix?keyword=pandora+plus+apk
- https://cdn.shopify.com/s/files/1/0437/5927/2090/files/thyroid_body_type_diet.pdf
- https://cdn.shopify.com/s/files/1/0438/5095/6960/files/winchester_1897_for_sale.pdf
- https://cdn.shopify.com/s/files/1/0430/6753/9623/files/32729379467.pdf
- https://a0ccc12d-047c-4706-aaf1-b3e77c3bd8b9.filesusr.com/ugd/610d21_75961537611745f0987d67db48c0cda3.pdf?index=true
- https://e6e9c26d-1d5f-457e-baee-8647390738ee.filesusr.com/ugd/c57cae_31d00e84536645a49a5716fd804be307.pdf?index=true
- https://086939ca-4bfe-4bc8-b57f-0f19a6d2b396.filesusr.com/ugd/035627_c0b00e33bf45464098dbd0cbc509a4e5.pdf?index=true
- https://9c05afd2-1a8b-43f5-adf8-0587100365ff.filesusr.com/ugd/b463f2_8bf53c5d9c8b4613a31019dbfdb534de.pdf?index=true
- http://files.alliancebulldogs.org/uploads/1/3/1/4/131455158/b0e58437118ae5.pdf
- http://tajev.harrisburgvictimhelp.org/uploads/1/3/1/3/131398222/6038713.pdf
- http://files.warungfalafelbali.com/uploads/1/3/1/4/131453944/ca44947fd.pdf
- https://cdn.shopify.com/s/files/1/0433/5196/5855/files/carbonato_de_litio_efectos_adversos.pdf
- https://cdn.shopify.com/s/files/1/0437/7437/8138/files/xatojoxege.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- cdn.shopify.com
- a0ccc12d-047c-4706-aaf1-b3e77c3bd8b9.filesusr.com
- e6e9c26d-1d5f-457e-baee-8647390738ee.filesusr.com
- 086939ca-4bfe-4bc8-b57f-0f19a6d2b396.filesusr.com
- 9c05afd2-1a8b-43f5-adf8-0587100365ff.filesusr.com
- files.alliancebulldogs.org
- tajev.harrisburgvictimhelp.org
- files.warungfalafelbali.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report