MALICIOUS — dcf9ad_d173f10791234e7f8ea569841c605644.pdf
MALICIOUS — dcf9ad_d173f10791234e7f8ea569841c605644.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ad1deeab1a2041d0a36e478914073732c0f6d6393880c36a72c665ff1acb4b49 - SHA-1:
78b56f447fcd95a1c9aa69c4b14ce444145592e8 - MD5:
9ef8b8a7ae1abecbe25ba72859c7fb1d - ssdeep:
768:GgGzpDGDViQcvHnujZFtI9gK1oWc1dF1Xm48BBswmvKeDX52m55yuZKh/A:TGF6CvyGCnBX5m48BBFSzJ2m5tZKh/A - TLSH:
T14733AFF350A7DE8C7A8B9B43A9AA009DB14BD3CD2022679454D87BBCC47C2FD6D41960 - Submitted as: dcf9ad_d173f10791234e7f8ea569841c605644.pdf
- File type: pdf · Size: 47693 bytes
- Verdict: malicious (95/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 7 weighted signals:
- Embedded link rated malicious by URL analysis: https://cc11f833-bd91-4cdd-b554-b7d65bb81d7b.filesusr.com/ugd/26481d_b24e0109e3c64274af2f59e7999c555e.pdf?index=true - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=rollercoaster+tycoon+3+iso+pc, http://veburovoz.yodha.net/uploads/1/3/2/7/132740494/fezizo-fobilu.pdf, http://nivax.rolianlab.com/uploads/1/3/2/3/132302999/4317419.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/wix?keyword=rollercoaster+tycoon+3+iso+pc
- http://veburovoz.yodha.net/uploads/1/3/2/7/132740494/fezizo-fobilu.pdf
- http://nivax.rolianlab.com/uploads/1/3/2/3/132302999/4317419.pdf
- http://files.forestbooks.net/uploads/1/3/1/4/131453350/bederema.pdf
- http://doselez.melindatuhus.net/uploads/1/3/0/8/130813115/domasisipuk.pdf
- https://26b34fd8-5e4e-4a3e-bfea-e1d5681bf8f2.filesusr.com/ugd/dcf311_dfcc6cb60d834e718fb75d14b693fad0.pdf?index=true
- https://1de5f78d-fb8d-4477-9ff2-59abc8e372b1.filesusr.com/ugd/43d598_843839ed58ea431b85af770ead668548.pdf?index=true
- https://d782772a-88ee-44a3-8935-ff773e862675.filesusr.com/ugd/ed8107_9c783dc6737244e5915c2927b2de466f.pdf?index=true
- https://cc11f833-bd91-4cdd-b554-b7d65bb81d7b.filesusr.com/ugd/26481d_b24e0109e3c64274af2f59e7999c555e.pdf?index=true
- https://8422032e-4020-4806-a76c-7ee7a2f385b0.filesusr.com/ugd/d4a9d6_ee30031560874662bdc95d416a4ef030.pdf?index=true
- http://files.msjsport.net/uploads/1/3/0/7/130739503/f205b8f59791877.pdf
- http://files.mrstuckeysclass.com/uploads/1/3/0/7/130776841/4143467.pdf
- http://nanafuga.practicalteacherresearch.com/uploads/1/3/0/7/130740025/dovakiz.pdf
- https://7048aa0a-ea91-4e9b-b04e-3e9a0e4c3859.filesusr.com/ugd/865d50_681b4ec744a4486a9d956108f98b2fd1.pdf?index=true
- https://f9ccc76c-a0f8-4f41-889d-31a28615173a.filesusr.com/ugd/db93e9_84875dc1c7764b7ea4415cfc08fd2f96.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- veburovoz.yodha.net
- nivax.rolianlab.com
- files.forestbooks.net
- doselez.melindatuhus.net
- 26b34fd8-5e4e-4a3e-bfea-e1d5681bf8f2.filesusr.com
- 1de5f78d-fb8d-4477-9ff2-59abc8e372b1.filesusr.com
- d782772a-88ee-44a3-8935-ff773e862675.filesusr.com
- cc11f833-bd91-4cdd-b554-b7d65bb81d7b.filesusr.com
- 8422032e-4020-4806-a76c-7ee7a2f385b0.filesusr.com
- files.msjsport.net
- files.mrstuckeysclass.com
- nanafuga.practicalteacherresearch.com
- 7048aa0a-ea91-4e9b-b04e-3e9a0e4c3859.filesusr.com
- f9ccc76c-a0f8-4f41-889d-31a28615173a.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report