MALICIOUS — 221eaa_692a2e879848409bb5b5a0655187830a.pdf
MALICIOUS — 221eaa_692a2e879848409bb5b5a0655187830a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
db9695d2871098c63befc7961a4815fe5fb320418bfb49fb963158a782d5ae06 - SHA-1:
743df2e5878390a0c38f43dbbe07400c45c16465 - MD5:
4217fa869b203091ec51281dc188eb17 - ssdeep:
1536:XGFxVhapfQnzqJ29sZlP1aV+YmvKm35HcOduaWoGzGGkC2x:2Fxaz2OZlP1DYmvKo5fuaWZGGkJ - TLSH:
T1BF37C0F3408BEE8C3ACBAB43ACA61198B505E68C7172979458CDB76C897C27C5F50E11 - Submitted as: 221eaa_692a2e879848409bb5b5a0655187830a.pdf
- File type: pdf · Size: 70536 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=calculating+kinetic+and+potential+energy+worksheet, https://cdn.shopify.com/s/files/1/0437/7355/8935/files/biological_control_of_insect_pests_and_weeds.pdf, https://cdn.shopify.com/s/files/1/0434/5544/7202/files/83355713030.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/wix?keyword=calculating+kinetic+and+potential+energy+worksheet
- https://cdn.shopify.com/s/files/1/0437/7355/8935/files/biological_control_of_insect_pests_and_weeds.pdf
- https://cdn.shopify.com/s/files/1/0434/5544/7202/files/83355713030.pdf
- https://cdn.shopify.com/s/files/1/0428/2905/4118/files/87121016621.pdf
- https://0d9e6537-3130-4746-aea7-c2645db74d5b.filesusr.com/ugd/0582e0_680d2328712f4e36b3ab0c2110483e16.pdf?index=true
- https://1200f017-1b96-4a48-96f4-2e63fdfa77f5.filesusr.com/ugd/f4de5e_c29987fa28f64607977e57a002015341.pdf?index=true
- https://fccdc852-50a6-48e3-9c4a-b4c849aaa274.filesusr.com/ugd/48bf55_934433f63a7041558068433082951ff4.pdf?index=true
- https://89eb978c-e554-4fd4-a1a6-ab46ec5e00bb.filesusr.com/ugd/e948c1_0c2f77f652244a0f840c1ecabf4b1407.pdf?index=true
- http://moraweti.farmgirlseggs.com/uploads/1/3/0/7/130775727/7498537d80.pdf
- http://xafajol.isabelsherk.com/uploads/1/3/1/3/131379730/7126304.pdf
- http://files.fiddleheadmarina.com/uploads/1/3/1/8/131856131/4625213.pdf
- https://6a33ce8a-b432-4fa1-9baf-d66b13feb261.filesusr.com/ugd/5ea691_fa2460f990274affbe30371097f1a6ab.pdf?index=true
- https://21f027f9-b5f7-4470-9fef-8ec77d8d1f55.filesusr.com/ugd/d5415a_024ee92748c24a698d0de5e0da0a4a05.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- cdn.shopify.com
- 0d9e6537-3130-4746-aea7-c2645db74d5b.filesusr.com
- 1200f017-1b96-4a48-96f4-2e63fdfa77f5.filesusr.com
- fccdc852-50a6-48e3-9c4a-b4c849aaa274.filesusr.com
- 89eb978c-e554-4fd4-a1a6-ab46ec5e00bb.filesusr.com
- moraweti.farmgirlseggs.com
- xafajol.isabelsherk.com
- files.fiddleheadmarina.com
- 6a33ce8a-b432-4fa1-9baf-d66b13feb261.filesusr.com
- 21f027f9-b5f7-4470-9fef-8ec77d8d1f55.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report