MALICIOUS — 3e5db3_a720810a04384da486918a178298e440.pdf
MALICIOUS — 3e5db3_a720810a04384da486918a178298e440.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e0ab27aa70ac52e5fd3b4b67058e027d61d6df52a4db972868fb0168b27fa837 - SHA-1:
fdc1298ceff2b319e99fbe943079aef1d88da21e - MD5:
5548c2edf93767405b11801e63e981f7 - ssdeep:
768:1gGzpDsd9+Re2v2kiGox6Xre8ldmvg/relsLLdp5Igo6PA8zbwsvSiaLFq:mGF4+vfiG26b3dMMakpVXbFSRLFq - TLSH:
T11F33BFF38057DCCDAACE5B1BBC960014554AEB4D72229774188D772CC9AC7BC9E80971 - Submitted as: 3e5db3_a720810a04384da486918a178298e440.pdf
- File type: pdf · Size: 48919 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.com/wix?keyword=cello+harmonics+notation+chart, https://54ff2955-3141-4b41-ac3b-48a91df226ab.filesusr.com/ugd/64bd79_1ede0eb3b4b843b9afeb0769c93a51ff.pdf?index=true, https://22ef02d2-72e1-4025-8a5d-dd712ea98951.filesusr.com/ugd/26f730_7815485aabc345f892cb18dfc503f3ec.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/wix?keyword=cello+harmonics+notation+chart
- https://54ff2955-3141-4b41-ac3b-48a91df226ab.filesusr.com/ugd/64bd79_1ede0eb3b4b843b9afeb0769c93a51ff.pdf?index=true
- https://22ef02d2-72e1-4025-8a5d-dd712ea98951.filesusr.com/ugd/26f730_7815485aabc345f892cb18dfc503f3ec.pdf?index=true
- https://179bb840-54a5-40ad-ae12-fd54e446d515.filesusr.com/ugd/e3325f_72ca0e0f7a254b4284967f350a8c5937.pdf?index=true
- http://files.kmartialarts.com/uploads/1/3/1/3/131398091/geribanimap.pdf
- https://2e0808d2-9f5a-411e-9ba6-dc334ba68ab9.filesusr.com/ugd/735189_83d562892c9046f39a0950375827ebdf.pdf?index=true
- https://98bec581-5109-4769-9dc3-3468ca30ac03.filesusr.com/ugd/60e703_a386e94fb9cd4d1b9374cf1167e473fc.pdf?index=true
- https://9922c089-ceac-4fa1-a32c-105d29d140cc.filesusr.com/ugd/dcf9ad_02b99cc910254a08b70f02757f093c48.pdf?index=true
- https://0e87eb3d-a36f-426e-90c4-fb22fb699c71.filesusr.com/ugd/9e14ca_a984348f8b544970ae2d2c6909477790.pdf?index=true
- https://cdn.shopify.com/s/files/1/0432/1961/5904/files/46625744273.pdf
- https://cdn.shopify.com/s/files/1/0434/3745/7574/files/diferencia_entre_celula_eucariota_y_procariota_cuadro_comparativo.pdf
- https://cdn.shopify.com/s/files/1/0430/0124/9955/files/padepopazolelezobufezuku.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- 54ff2955-3141-4b41-ac3b-48a91df226ab.filesusr.com
- 22ef02d2-72e1-4025-8a5d-dd712ea98951.filesusr.com
- 179bb840-54a5-40ad-ae12-fd54e446d515.filesusr.com
- files.kmartialarts.com
- 2e0808d2-9f5a-411e-9ba6-dc334ba68ab9.filesusr.com
- 98bec581-5109-4769-9dc3-3468ca30ac03.filesusr.com
- 9922c089-ceac-4fa1-a32c-105d29d140cc.filesusr.com
- 0e87eb3d-a36f-426e-90c4-fb22fb699c71.filesusr.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report