MALICIOUS — 95089d_ea02f0a968c145c49d32b7f52fb616ae.pdf
MALICIOUS — 95089d_ea02f0a968c145c49d32b7f52fb616ae.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d5a6966f86ee0a87fd1bcc3df7fe17f28933227f6b69bbc96dc4f2aa6b349204 - SHA-1:
12bc755d058ffcbf3ff143e8a8e9c30378ac948e - MD5:
5204677d105fecd1259ad29be45ef3a7 - ssdeep:
768:NxYgGzpDxUlq/vLoq4G7xBVH4WkAFhWaS+Xrz6w9Fc6YjxRdviIN+cRXqBXynRV:b1GFtPf7HFfEybdv8dvocWynRV - TLSH:
T11A32AFF35093DCCD798A6B076EB710A8A158CB8C3022EA6455CC775DC4F86FC6E50A61 - Submitted as: 95089d_ea02f0a968c145c49d32b7f52fb616ae.pdf
- File type: pdf · Size: 46598 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 8 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.club/wix?keyword=grace+based+parenting+workbook+pdf, https://cdn.shopify.com/s/files/1/0484/9785/2577/files/sutotanijegeji.pdf, https://cdn.shopify.com/s/files/1/0431/5598/0439/files/xunilapalabejow.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/wix?keyword=grace+based+parenting+workbook+pdf
- https://cdn.shopify.com/s/files/1/0484/9785/2577/files/sutotanijegeji.pdf
- https://cdn.shopify.com/s/files/1/0431/5598/0439/files/xunilapalabejow.pdf
- https://cdn.shopify.com/s/files/1/0436/6116/4697/files/dabukuxozizikedipurivujuw.pdf
- https://cdn.shopify.com/s/files/1/0447/5705/7687/files/china_visa_application_form_brunei.pdf
- http://xogobufip.memberoftwotribes.com/uploads/1/3/1/4/131411896/zivenux_belifufetibo_toguxir.pdf
- http://dojoki.englishcentral.info/uploads/1/3/0/7/130776485/sadonizoxupinolu.pdf
- http://nekubu.uplayjewishmusic.com/uploads/1/3/1/1/131163507/bebolakibubuzow.pdf
- http://nikawu.asiaclimateforum.com/uploads/1/3/0/8/130813780/6697fa6d6b.pdf
- http://files.mattakehurst.net/uploads/1/3/0/7/130740323/diribabebada_suxarebesu_fopigagagamo.pdf
- http://files.hairpinmuseum.org/uploads/1/3/0/7/130738969/pokuxibisuwepowa.pdf
- https://cdn.shopify.com/s/files/1/0434/3513/1036/files/77199675045.pdf
- https://cdn.shopify.com/s/files/1/0437/0969/4107/files/18312439692.pdf
- https://cdn.shopify.com/s/files/1/0434/1035/8439/files/ccleaner_pro_android_4pda.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.club
- cdn.shopify.com
- xogobufip.memberoftwotribes.com
- dojoki.englishcentral.info
- nekubu.uplayjewishmusic.com
- nikawu.asiaclimateforum.com
- files.mattakehurst.net
- files.hairpinmuseum.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report