MALICIOUS — 7be1cd_40e017d5b9c44f57a075522de4473dab.pdf
MALICIOUS — 7be1cd_40e017d5b9c44f57a075522de4473dab.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
9d916e7372dbe730e630196ccd4b07f5849e7169e8fd251f6426bb1ef92e0dde - SHA-1:
eb46284252140df370a505baa47efc2db5993db5 - MD5:
b54decd8b887090435cde693429b2949 - ssdeep:
768:2gGzpDC2Nflved5UHHc00i6B48ArFGNEBKKNPvSMUyDb/:jGF+6JqUc0R6irFkSKKNPvLUyDb/ - TLSH:
T1E032AFF30097EC8C7BCBAF175E6B11296086E78D6023975444D97ABCC5BC6ED6E10A20 - Submitted as: 7be1cd_40e017d5b9c44f57a075522de4473dab.pdf
- File type: pdf · Size: 46547 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.cc/wix?keyword=dry+september+analysis, http://zoganexa.susannawesleyumc.org/uploads/1/3/1/4/131452821/3507305.pdf, http://xakivi.jocelynphotoblogs.co.uk/uploads/1/3/1/3/131384605/6377352.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/wix?keyword=dry+september+analysis
- http://zoganexa.susannawesleyumc.org/uploads/1/3/1/4/131452821/3507305.pdf
- http://xakivi.jocelynphotoblogs.co.uk/uploads/1/3/1/3/131384605/6377352.pdf
- http://wewipi.surrey-epc.co.uk/uploads/1/3/1/0/131069806/piboropadisug_morafovej.pdf
- http://delujux.cabinetryconnect.com/uploads/1/3/1/8/131856190/nonerodatajanuvu.pdf
- http://jivirir.youtwocantango.com/uploads/1/3/0/7/130776246/39951212930395.pdf
- https://d5d7bcb1-0078-4473-be73-6f93bd12a019.filesusr.com/ugd/4a2613_f2445b3885cc4c60983103d1c77759cc.pdf?index=true
- https://85a66ee8-b731-4b84-98c4-413de16b294a.filesusr.com/ugd/ab922d_5ae0a73e28244199a744167127b1443a.pdf?index=true
- https://f0282ac7-7221-42a1-abba-e3ddf2fda63d.filesusr.com/ugd/5f5755_2d2663cef14b41c6af82f98ce041fcbe.pdf?index=true
- https://e42ce207-d846-4db6-8c56-04e00455f6bd.filesusr.com/ugd/eda9ba_96117452a79c439cadb930dfeffe3110.pdf?index=true
- http://files.northernirelandteacher.com/uploads/1/3/0/8/130814340/2a310a.pdf
- http://files.historyneedsyou.com/uploads/1/3/1/1/131164032/8614192.pdf
- http://files.highalpinegenetics.com/uploads/1/3/2/6/132682868/zemeked.pdf
- http://fovafopiv.alishameyer.com/uploads/1/3/0/7/130739430/nuvaxifatupegi.pdf
- https://136e6361-ab43-4f80-869a-f18666b49f77.filesusr.com/ugd/b463f2_f05a7abd33ee4ebe960a9c0ddeb37b79.pdf?index=true
- https://58e6d073-7f92-4e33-adb3-d9c0a5390777.filesusr.com/ugd/ebc5f9_a85ade78571f4006af8f596bb2184f27.pdf?index=true
- https://6f86f782-d66a-42f2-886f-231f6b17cc2e.filesusr.com/ugd/3f1130_154ea4523e464dd4a8396810b5e30652.pdf?index=true
- https://cdddc31a-72ae-4b00-a5cb-76c2cfdcecbb.filesusr.com/ugd/cfbfd2_44f4e8d1b377432fb070298bd46ca378.pdf?index=true
- https://09452c1b-0b51-46bb-9181-9d755442705e.filesusr.com/ugd/e32576_4e8f113b76c64a558ef64d723b4d0516.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.cc
- zoganexa.susannawesleyumc.org
- xakivi.jocelynphotoblogs.co.uk
- wewipi.surrey-epc.co.uk
- delujux.cabinetryconnect.com
- jivirir.youtwocantango.com
- d5d7bcb1-0078-4473-be73-6f93bd12a019.filesusr.com
- 85a66ee8-b731-4b84-98c4-413de16b294a.filesusr.com
- f0282ac7-7221-42a1-abba-e3ddf2fda63d.filesusr.com
- e42ce207-d846-4db6-8c56-04e00455f6bd.filesusr.com
- files.northernirelandteacher.com
- files.historyneedsyou.com
- files.highalpinegenetics.com
- fovafopiv.alishameyer.com
- 136e6361-ab43-4f80-869a-f18666b49f77.filesusr.com
- 58e6d073-7f92-4e33-adb3-d9c0a5390777.filesusr.com
- 6f86f782-d66a-42f2-886f-231f6b17cc2e.filesusr.com
- cdddc31a-72ae-4b00-a5cb-76c2cfdcecbb.filesusr.com
- 09452c1b-0b51-46bb-9181-9d755442705e.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report