MALICIOUS — 9117e0_66c720a1148d4c5da36a985d0840ffc6.pdf
MALICIOUS — 9117e0_66c720a1148d4c5da36a985d0840ffc6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
ea4b0d7efa53b9a3d663a6ff069f86ce00b2c80ebd29bec234a10532b03ea512 - SHA-1:
07f6f82a739b61db4d7fed078fb05b8f5e76089b - MD5:
e618dfc63219a2dd5a24ac7121e7a972 - ssdeep:
768:wgGzpD+6bdlFcmQMskotUwY4Uv0+404GCfq5vC:dGFq6mmQMsmwnT+f4zC5vC - TLSH:
T18C308DF344DBED8C7A8B6B036DA711696056C3886227E76058D9336CC0BC2BCAF50871 - Submitted as: 9117e0_66c720a1148d4c5da36a985d0840ffc6.pdf
- File type: pdf · Size: 36080 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=fifa+19+apk+download+apkpure, http://files.prescottvalleylittleleague.com/uploads/1/3/0/8/130813888/jobozopogo-buxufiwaj-xuxodowa-dawafasa.pdf, http://files.gardencityfsc.com/uploads/1/3/2/3/132302759/7433591.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/wix?keyword=fifa+19+apk+download+apkpure
- http://files.prescottvalleylittleleague.com/uploads/1/3/0/8/130813888/jobozopogo-buxufiwaj-xuxodowa-dawafasa.pdf
- http://files.gardencityfsc.com/uploads/1/3/2/3/132302759/7433591.pdf
- http://files.metlifelostpensions.com/uploads/1/3/1/3/131381772/tudinadajuxanigolib.pdf
- http://files.blackbayhorsefarm.ca/uploads/1/3/0/7/130775522/tipuzudesum-bexufoxiwola.pdf
- http://files.timwilsonfineart.com/uploads/1/3/1/4/131438245/1360119.pdf
- https://0838145a-ab9f-4f99-86d6-acf895978f9b.filesusr.com/ugd/724fb5_ff67cf5cb8a34837a4924d830ec8abe9.pdf?index=true
- https://007253ab-0c22-4ced-b3d0-563ba99d4455.filesusr.com/ugd/baef12_811dd8e6b9604dccb3101941acf9c077.pdf?index=true
- https://09ca9db3-51fd-4c7e-815d-e845b677deff.filesusr.com/ugd/15ebe2_2243da0484f34bcb8d23ee4d107f2b18.pdf?index=true
- https://cc191a37-01ff-446f-9160-0ca68af0a974.filesusr.com/ugd/baef12_ea3f2b33da5c44be99be88ebfcb82088.pdf?index=true
- https://81cb9cc9-f1a7-4053-8d03-09200d4c8e78.filesusr.com/ugd/6a7407_c62ff4e3b9624001ac3ec103221b0af9.pdf?index=true
- https://35292723-5805-4151-9b21-aefcc5b2b7f5.filesusr.com/ugd/7e0eb0_c543618c99ed464692147c3366a5faeb.pdf?index=true
- https://2867e3a4-5af3-407e-8051-bcab6f7dffbd.filesusr.com/ugd/76aeb6_851b968a86fd4309b7537896c09802f6.pdf?index=true
- https://994170e0-5e6f-44fc-b6d0-ac5f787147ed.filesusr.com/ugd/60ffa2_28a4876b356b4d01ba91fd720fa4fe4e.pdf?index=true
- https://ffea93e8-1295-496d-b601-fe17127891ad.filesusr.com/ugd/e50c99_d70d100679f6428d87d5068bf81ae837.pdf?index=true
- https://cbaffc75-bc4f-44f5-8692-da84057067a5.filesusr.com/ugd/440e29_06d2edbf01304fd4a642d8a05b4e1515.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- files.prescottvalleylittleleague.com
- files.gardencityfsc.com
- files.metlifelostpensions.com
- files.blackbayhorsefarm.ca
- files.timwilsonfineart.com
- 0838145a-ab9f-4f99-86d6-acf895978f9b.filesusr.com
- 007253ab-0c22-4ced-b3d0-563ba99d4455.filesusr.com
- 09ca9db3-51fd-4c7e-815d-e845b677deff.filesusr.com
- cc191a37-01ff-446f-9160-0ca68af0a974.filesusr.com
- 81cb9cc9-f1a7-4053-8d03-09200d4c8e78.filesusr.com
- 35292723-5805-4151-9b21-aefcc5b2b7f5.filesusr.com
- 2867e3a4-5af3-407e-8051-bcab6f7dffbd.filesusr.com
- 994170e0-5e6f-44fc-b6d0-ac5f787147ed.filesusr.com
- ffea93e8-1295-496d-b601-fe17127891ad.filesusr.com
- cbaffc75-bc4f-44f5-8692-da84057067a5.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report