MALICIOUS — 56530209089.pdf
MALICIOUS — 56530209089.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (70/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
bde27a782c93961efa5796ee66a84d96aa31ad8051ef02099ff436894aa8c7c7 - SHA-1:
4d1c4a82b238bb94a78db683eb9d93fa5d2b800f - MD5:
c24d2af144ce8a5b18830ef47a36edd6 - ssdeep:
768:FgGzpDfaNW85eDAlze8YABAEeFEUMCmYFb2ZUonj4VJBTd3dKlRi:WGFLwuAiqUp+nniJ33dKlRi - TLSH:
T1BF329DF350A7EE8C768A6B03ACB70556618AC34DA133E7B055C87B6CC0BC2AC7E50950 - Submitted as: 56530209089.pdf
- File type: pdf · Size: 45766 bytes
- Verdict: malicious (70/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 70/100 is the fusion of 4 weighted signals:
- Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://cctraff.ru/strik?keyword=harvest+moon+light+of+hope+marriage, https://site-1037276.mozfiles.com/files/1037276/90390907710.pdf, https://site-1039802.mozfiles.com/files/1039802/83121319550.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=harvest+moon+light+of+hope+marriage
- https://site-1037276.mozfiles.com/files/1037276/90390907710.pdf
- https://site-1039802.mozfiles.com/files/1039802/83121319550.pdf
- https://site-1039332.mozfiles.com/files/1039332/polut.pdf
- https://site-1043764.mozfiles.com/files/1043764/96570078936.pdf
- https://site-1039529.mozfiles.com/files/1039529/78028789803.pdf
- http://zizawo.themathbutler.com/uploads/1/3/1/3/131382028/vusukopopiginalul.pdf
- http://bomexoz.remnantsbarbersho.org/uploads/1/3/0/8/130814070/6877d9f873da.pdf
- http://files.diekmancounseling.com/uploads/1/3/1/4/131483025/xijapopigigelaz.pdf
- http://files.vanitiesspa.com/uploads/1/3/2/7/132740541/zikosowadezamod.pdf
- http://bagupewam.namicoloradosprings.org/uploads/1/3/1/4/131454521/d22a079e64827f7.pdf
- https://cdn.shopify.com/s/files/1/0479/2254/4807/files/jawivikimatisijukow.pdf
- https://cdn.shopify.com/s/files/1/0438/8493/7384/files/rebuilt_manual_transmission_break_in.pdf
- https://cdn.shopify.com/s/files/1/0436/8800/1689/files/17789180582.pdf
- https://uploads.strikinglycdn.com/files/7542fe47-c852-4ab9-8480-9c5295cb52a6/17894237101.pdf
- https://uploads.strikinglycdn.com/files/e1453857-f578-45e1-bc9d-28e9aa4904f6/tugemurosabugolom.pdf
- https://uploads.strikinglycdn.com/files/7102a31e-be27-4b25-b322-5de3a747a629/posesagopixat.pdf
- https://uploads.strikinglycdn.com/files/ef10e947-8e02-4c85-986b-9e628b35790a/42904951385.pdf
- https://uploads.strikinglycdn.com/files/a84fd132-1a5b-46a4-b280-66b1644e0bdd/15009156071.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1037276.mozfiles.com
- site-1039802.mozfiles.com
- site-1039332.mozfiles.com
- site-1043764.mozfiles.com
- site-1039529.mozfiles.com
- zizawo.themathbutler.com
- bomexoz.remnantsbarbersho.org
- files.diekmancounseling.com
- files.vanitiesspa.com
- bagupewam.namicoloradosprings.org
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report