MALICIOUS — de3d83_bf40d178a7c94102b24c6b1a56903ac1.pdf
MALICIOUS — de3d83_bf40d178a7c94102b24c6b1a56903ac1.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
aadce8553e34e50f0d863040acc439b4071d0255f035e6829bbc0fc639b2d112 - SHA-1:
0a8a956d70bd860d5966a89b846bda79485b2f4e - MD5:
e25a2dc2ea1e5175e8661867d9812b23 - ssdeep:
768:ogGzpDl+A4jw9RiwVnIh3sfEQdlDEX9tzoWmpihi41vcJLAm14OwAWLdO:lGFZCwOh8/LQWWmD4RcxV149AWLdO - TLSH:
T101319EF31197EC4C6AC75F03AFDA105D9187E6896033B6B05898B62CC4BC6FD6E10A61 - Submitted as: de3d83_bf40d178a7c94102b24c6b1a56903ac1.pdf
- File type: pdf · Size: 42988 bytes
- Verdict: malicious (88/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.PDF.Agent.gen (rule
HEUR:Trojan.PDF.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.link/wix?keyword=the+major+wind+belts+of+the+world+are+generated+by+the+lowermost, https://f2000082-9d0d-4d58-9b92-64c04d768dc6.filesusr.com/ugd/bba345_748907ce45c44423a491cf49fffa6150.pdf?index=true, https://26b916bc-27a1-413e-933b-09db8b8b9c38.filesusr.com/ugd/edb4a7_9dc47ed1359044e597f54a3a9bb90663.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/wix?keyword=the+major+wind+belts+of+the+world+are+generated+by+the+lowermost
- https://f2000082-9d0d-4d58-9b92-64c04d768dc6.filesusr.com/ugd/bba345_748907ce45c44423a491cf49fffa6150.pdf?index=true
- https://26b916bc-27a1-413e-933b-09db8b8b9c38.filesusr.com/ugd/edb4a7_9dc47ed1359044e597f54a3a9bb90663.pdf?index=true
- https://70d7f43f-4145-4d6b-84ca-45929496e8d4.filesusr.com/ugd/93c935_e70c809270284198b53fd595419da4d5.pdf?index=true
- https://1e23c6c1-8353-4330-8201-30fb12d5e459.filesusr.com/ugd/625844_db26f6fd97b24eb7b488c99b67dc7bdb.pdf?index=true
- https://9bf35b4e-53a1-482d-a6d8-5a512df5d2bf.filesusr.com/ugd/b463f2_9bb0ff882c6d41a88a570837d369af8b.pdf?index=true
- https://09ff10dd-af4c-472f-bd7f-f1edddd52c6d.filesusr.com/ugd/3ed902_bb17fcff288642e79e2b91b28a5eca0e.pdf?index=true
- https://78d9ee74-dde0-47f5-b89c-bb93eece8b86.filesusr.com/ugd/81d6a4_6dd2eb675c95467a85cdb26e2c7b87bf.pdf?index=true
- https://468a6eb5-8586-4a86-b60c-6bee64e84b06.filesusr.com/ugd/610d21_30f0fd092b594a128a76266673c7e74e.pdf?index=true
- https://fd96792e-2467-4589-a1cf-c19755ffa7e5.filesusr.com/ugd/b42fd6_dd459fd97f7448118d39270b2eaff3fb.pdf?index=true
- https://922f97ee-02f7-42a9-afb1-103697487136.filesusr.com/ugd/c5d40f_9b76a8a6fbcb4afc888923dea9d8e51f.pdf?index=true
- http://pinox.dscampers.co.uk/uploads/1/3/2/7/132712315/wokisu.pdf
- http://files.kivahouse.net/uploads/1/3/0/9/130969334/momaratewerolon-watonakuto-nifigemipon-mupusenotow.pdf
- https://cdn.shopify.com/s/files/1/0427/8353/9366/files/rawiz.pdf
- https://cdn.shopify.com/s/files/1/0437/9544/7970/files/78424624352.pdf
- https://cdn.shopify.com/s/files/1/0429/1044/9830/files/depreciation_methods_questions_and_answers.pdf
- https://cdn.shopify.com/s/files/1/0435/2029/5064/files/lipegavonelovinonotil.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.link
- f2000082-9d0d-4d58-9b92-64c04d768dc6.filesusr.com
- 26b916bc-27a1-413e-933b-09db8b8b9c38.filesusr.com
- 70d7f43f-4145-4d6b-84ca-45929496e8d4.filesusr.com
- 1e23c6c1-8353-4330-8201-30fb12d5e459.filesusr.com
- 9bf35b4e-53a1-482d-a6d8-5a512df5d2bf.filesusr.com
- 09ff10dd-af4c-472f-bd7f-f1edddd52c6d.filesusr.com
- 78d9ee74-dde0-47f5-b89c-bb93eece8b86.filesusr.com
- 468a6eb5-8586-4a86-b60c-6bee64e84b06.filesusr.com
- fd96792e-2467-4589-a1cf-c19755ffa7e5.filesusr.com
- 922f97ee-02f7-42a9-afb1-103697487136.filesusr.com
- pinox.dscampers.co.uk
- files.kivahouse.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report