MALICIOUS — e2b09b_8799e1e76a9f4f3d99bb756767c74a77.pdf
MALICIOUS — e2b09b_8799e1e76a9f4f3d99bb756767c74a77.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
d4713b5b9ceeaed89b2415394b1934323d5b63a41214680e46173e214e106bde - SHA-1:
49cb472ba2255da963d7441bc2357488334ad579 - MD5:
1d282393248675a28d2993395ab26868 - ssdeep:
768:pgGzpDCTok/blIrFhy7FEXWBPKemcWu0PAO6jmzA6D+KptvbgElKUCJzyxhO:KGFWTBuryJkMCrc10PAOCmEFKpt1AyxE - TLSH:
T11332AEF35193CC8C7A8AAB139D93015C608AC6CE6127D3B404E87B6C84BC5FD6E41A65 - Submitted as: e2b09b_8799e1e76a9f4f3d99bb756767c74a77.pdf
- File type: pdf · Size: 45569 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.club/wix?keyword=wf+crd+svc+phone+number, https://474bc2b7-7c93-497f-a2cc-71493b8ddc3a.filesusr.com/ugd/33ab24_a27a889e38554549bb87e033af03279c.pdf?index=true, https://c93ceda7-4009-46b2-8421-880125a843a3.filesusr.com/ugd/ce14f3_79befbb6f80d4a2eb42e2ba10b2ae5d9.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/wix?keyword=wf+crd+svc+phone+number
- https://474bc2b7-7c93-497f-a2cc-71493b8ddc3a.filesusr.com/ugd/33ab24_a27a889e38554549bb87e033af03279c.pdf?index=true
- https://c93ceda7-4009-46b2-8421-880125a843a3.filesusr.com/ugd/ce14f3_79befbb6f80d4a2eb42e2ba10b2ae5d9.pdf?index=true
- https://1fe9b630-f808-11ea-a328-fc4dd43d38a6.filesusr.com/ugd/2b25b5_485d793debeb45bd9250f5940c6ed34d.pdf?index=true
- https://d782772a-88ee-44a3-8935-ff773e862675.filesusr.com/ugd/ed8107_9c783dc6737244e5915c2927b2de466f.pdf?index=true
- http://winek.maddogslair.com/uploads/1/3/2/7/132710621/c80e2cd39.pdf
- http://files.nekrubs.com/uploads/1/3/2/6/132681690/990145f2bb7.pdf
- http://zupuj.kiddylinguistics.com/uploads/1/3/0/8/130813528/178354d7a57ba.pdf
- http://veguvupok.jimgymsupply.com/uploads/1/3/0/7/130775350/kezijixugoki-sijopuxex.pdf
- http://ledelupow.soulmarkers.net/uploads/1/3/0/7/130775012/lubarojow-paxet.pdf
- http://files.bridlevale.com/uploads/1/3/0/7/130775838/2025624.pdf
- http://laraxi.augustdulcimerdaze.com/uploads/1/3/1/3/131383761/955370.pdf
- http://vuzanuk.kalituregundogs.com/uploads/1/3/0/8/130814761/8713686.pdf
- https://977de6ec-4576-4b60-ac96-97bb90d1c18d.filesusr.com/ugd/2994dd_36a6e4533c594a6097986cef6fd114cd.pdf?index=true
- https://8496119b-30b7-4f3f-94d1-1510522d5f09.filesusr.com/ugd/5bb01c_0dfe8496ddab4755a6711baf5faec18d.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.club
- 474bc2b7-7c93-497f-a2cc-71493b8ddc3a.filesusr.com
- c93ceda7-4009-46b2-8421-880125a843a3.filesusr.com
- 1fe9b630-f808-11ea-a328-fc4dd43d38a6.filesusr.com
- d782772a-88ee-44a3-8935-ff773e862675.filesusr.com
- winek.maddogslair.com
- files.nekrubs.com
- zupuj.kiddylinguistics.com
- veguvupok.jimgymsupply.com
- ledelupow.soulmarkers.net
- files.bridlevale.com
- laraxi.augustdulcimerdaze.com
- vuzanuk.kalituregundogs.com
- 977de6ec-4576-4b60-ac96-97bb90d1c18d.filesusr.com
- 8496119b-30b7-4f3f-94d1-1510522d5f09.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report