MALICIOUS — f1780b_fe01a5ebee344fb584cc87ca3b6ab59a.pdf
MALICIOUS — f1780b_fe01a5ebee344fb584cc87ca3b6ab59a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
9fd65a88efae98d82b6d668fb612164f5896ee79e04fbf53b6a753e6b3969424 - SHA-1:
c77c215ff67dfd7b171effa4cda7627bd4eb29e7 - MD5:
9c670acd9243c0af65c309f895917b6c - ssdeep:
768:DgGzpDMSWWrswGJbYZ3zm9oAvK7pQIU0NgUmKy3KpQBUI3PEYMBJ/TSM:8GFY0r2RYNNg8yXBLEhBJ7SM - TLSH:
T17D319EF36057EC8C7A8BAB03ADE711596086C68D71369B6015D87B2CC4BC6FC6F10A50 - Submitted as: f1780b_fe01a5ebee344fb584cc87ca3b6ab59a.pdf
- File type: pdf · Size: 42947 bytes
- Verdict: malicious (88/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.com/wix?keyword=test+dpc+4.0.5+apk, http://pijin.brijcommunity.org/uploads/1/3/2/3/132303354/mixawav_lunikufazujakoz_nobikok_segipegaxesol.pdf, http://larone.julianhistoricalsociety.org/uploads/1/3/0/7/130775997/5798511.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/wix?keyword=test+dpc+4.0.5+apk
- http://pijin.brijcommunity.org/uploads/1/3/2/3/132303354/mixawav_lunikufazujakoz_nobikok_segipegaxesol.pdf
- http://larone.julianhistoricalsociety.org/uploads/1/3/0/7/130775997/5798511.pdf
- http://jugureni.sukhikitchen.com/uploads/1/3/2/8/132815028/1be40f.pdf
- http://takoduti.bouncing2wellness.com/uploads/1/3/1/4/131452821/mebuvu.pdf
- https://cdn.shopify.com/s/files/1/0434/3765/4178/files/nuxakixiviwotanufalexafeg.pdf
- https://cdn.shopify.com/s/files/1/0436/8692/0347/files/84391355004.pdf
- https://cdn.shopify.com/s/files/1/0428/3046/3135/files/30241103325.pdf
- https://cdn.shopify.com/s/files/1/0435/6774/3139/files/design_and_analysis_of_algorithms_viva_questions_and_answers.pdf
- https://cdn.shopify.com/s/files/1/0467/9729/1671/files/53794960934.pdf
- http://nemumeze.studiob.agency/uploads/1/3/1/0/131070934/mefitowusogo.pdf
- http://files.onceupon-atime.com/uploads/1/3/1/4/131410158/5691824.pdf
- http://kipatuj.nolaclay.org/uploads/1/3/2/6/132681501/pojeloxivum.pdf
- http://doviti.gratiotdems.net/uploads/1/3/0/8/130813528/vexovojetegikorez.pdf
- https://5f6c9b04-a18f-4639-8fec-1461c3a4b497.filesusr.com/ugd/735189_8bffd376c7a244d996a0cb8a913f5680.pdf?index=true
- https://d33ba8b3-a666-4303-9248-0610a85f1f8e.filesusr.com/ugd/2994dd_d1cc7326e39349f4938ea291edcefcf0.pdf?index=true
- https://7265a101-a663-4bd2-ac10-7d52bfb80064.filesusr.com/ugd/35c6e2_00e9a7fac260470fac6bb1d0566fac98.pdf?index=true
- https://fd031e9c-2430-4e50-ab13-b22f204edfd7.filesusr.com/ugd/65b209_90ac8f1e7e2442d6a9d8b8ea4c25c2b3.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- pijin.brijcommunity.org
- larone.julianhistoricalsociety.org
- jugureni.sukhikitchen.com
- takoduti.bouncing2wellness.com
- cdn.shopify.com
- files.onceupon-atime.com
- kipatuj.nolaclay.org
- doviti.gratiotdems.net
- 5f6c9b04-a18f-4639-8fec-1461c3a4b497.filesusr.com
- d33ba8b3-a666-4303-9248-0610a85f1f8e.filesusr.com
- 7265a101-a663-4bd2-ac10-7d52bfb80064.filesusr.com
- fd031e9c-2430-4e50-ab13-b22f204edfd7.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
- nemumeze.studiob.agency
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report