MALICIOUS — db1da1_038148fc54104939b2319ff3988f6f76.pdf
MALICIOUS — db1da1_038148fc54104939b2319ff3988f6f76.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
cde7b99ab1dab492c393ab80a2ccb475f0fb18528b0a3f0a0a22f7cf7dd2b0c4 - SHA-1:
0a24173569d320a9b0ac5dc30a68a7f9de2b4047 - MD5:
9a988cc4c194cc6f5a6ef6a445171541 - ssdeep:
1536:RGF4IMv9SJ5Bzlv40soHT9vvP893Jdgau/Ju:0F43vMJ3zlv9HT93Pa3Jdxu8 - TLSH:
T13D36C0F32053EDCCABC96F13ADEA15181147D68921779A6018DD7B6CC4BC2BD6F20A60 - Submitted as: db1da1_038148fc54104939b2319ff3988f6f76.pdf
- File type: pdf · Size: 65645 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.me/wix?keyword=how+to+get+free+robux+easy+2020+july, http://files.adirondack90miler.com/uploads/1/3/1/3/131378990/3395584.pdf, http://nirofe.samanthagagnon.com/uploads/1/3/1/8/131872055/f8c781d22.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/wix?keyword=how+to+get+free+robux+easy+2020+july
- http://files.adirondack90miler.com/uploads/1/3/1/3/131378990/3395584.pdf
- http://nirofe.samanthagagnon.com/uploads/1/3/1/8/131872055/f8c781d22.pdf
- http://wazixut.standardpoodlesforsale.com/uploads/1/3/1/3/131378942/dorupumow.pdf
- http://tazog.amptheatreagency.co.uk/uploads/1/3/0/7/130776644/giboroninugixak-xafegipomami-fubutev.pdf
- https://6db29c89-a2b9-488c-820b-29aa5fab91c5.filesusr.com/ugd/6f53d7_98fa3f7afd6c43b2a5b5fddbea1c7789.pdf?index=true
- https://5807444f-183d-4c21-b57f-b741411f4489.filesusr.com/ugd/ab922d_9ec3c6586c8847c892092cbfd4f17232.pdf?index=true
- https://38c9532e-c41e-4115-a1e6-6584ea5c71ea.filesusr.com/ugd/7836c9_032f90d612dd4287af941f377af65e27.pdf?index=true
- https://698f0198-70a1-4677-be39-b8a696bda4b6.filesusr.com/ugd/a6e5e9_333a0030322f402ba21c2a5fd1eed475.pdf?index=true
- https://d01ddaca-8f3f-4c38-b54d-2ce333cc530c.filesusr.com/ugd/f08e01_8efdb059ba1143dd99aa8300918a67bb.pdf?index=true
- https://f372a0f4-10be-43da-b170-408ab6b551a7.filesusr.com/ugd/143c98_4fb94bc4f6624b86aec13f34d3274d29.pdf?index=true
- https://18ed90a5-c6d0-47bf-8045-068df66419c1.filesusr.com/ugd/2e4eb4_fd000ddd78bd4c2f81ec8675f89f31d1.pdf?index=true
- https://53dc6e79-4725-4aa4-a97f-233f5921c31b.filesusr.com/ugd/fe83c3_d378caa254d1478f9ed5043bdbae36ab.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.me
- files.adirondack90miler.com
- nirofe.samanthagagnon.com
- wazixut.standardpoodlesforsale.com
- tazog.amptheatreagency.co.uk
- 6db29c89-a2b9-488c-820b-29aa5fab91c5.filesusr.com
- 5807444f-183d-4c21-b57f-b741411f4489.filesusr.com
- 38c9532e-c41e-4115-a1e6-6584ea5c71ea.filesusr.com
- 698f0198-70a1-4677-be39-b8a696bda4b6.filesusr.com
- d01ddaca-8f3f-4c38-b54d-2ce333cc530c.filesusr.com
- f372a0f4-10be-43da-b170-408ab6b551a7.filesusr.com
- 18ed90a5-c6d0-47bf-8045-068df66419c1.filesusr.com
- 53dc6e79-4725-4aa4-a97f-233f5921c31b.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report