MALICIOUS — 868b90_0fd288d676574aef934e1f18428303b5.pdf
MALICIOUS — 868b90_0fd288d676574aef934e1f18428303b5.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
f98a270354ca53f562c7ea404b2509b93140122c7a64c05e39fdaf80ff617983 - SHA-1:
a52f3f3903d9e56dd908c7ad75c5e32810b8c1e0 - MD5:
1b41273817298a868b4bccaed486b7fc - ssdeep:
768:wWgGzpDFrIzOVoufoxz5c0aPuOxo78Z6KdsVCps5t852zJjCNciAAWPW59OC2IVl:+GFBlopOxogZrsosU52zUjAAWP0n2IVl - TLSH:
T16333AEF300A7ED8C6A86AB43ACB700541145C78D7132EBA159CD7B3CD97C2BE6E11960 - Submitted as: 868b90_0fd288d676574aef934e1f18428303b5.pdf
- File type: pdf · Size: 48011 bytes
- Verdict: malicious (88/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.club/wix?keyword=vshare+market+apk+download+for+android, http://files.peterrichardsart.com/uploads/1/3/1/8/131857213/57546e.pdf, http://files.primalfitnessleague.com/uploads/1/3/0/9/130969499/xerodikuzu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/wix?keyword=vshare+market+apk+download+for+android
- http://files.peterrichardsart.com/uploads/1/3/1/8/131857213/57546e.pdf
- http://files.primalfitnessleague.com/uploads/1/3/0/9/130969499/xerodikuzu.pdf
- http://gajoru.rstne.com/uploads/1/3/2/8/132814930/8351640.pdf
- https://cdn.shopify.com/s/files/1/0429/4564/2663/files/bi-_84_form_south_africa.pdf
- https://cdn.shopify.com/s/files/1/0428/9540/9311/files/nebirobemekuwidugukiv.pdf
- https://cdn.shopify.com/s/files/1/0430/9375/4009/files/kagevafojajep.pdf
- https://cdn.shopify.com/s/files/1/0431/8678/2369/files/bescherelle_cole_gratuit.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/zetuvoveluganimuwejipas.pdf
- https://cdn.shopify.com/s/files/1/0440/3019/7925/files/clinical_cases_in_anesthesia_free_download.pdf
- https://cdn.shopify.com/s/files/1/0438/0862/0701/files/fawaxexafebuvanesetorilur.pdf
- https://cdn.shopify.com/s/files/1/0437/4478/8634/files/luvoxepopisifaf.pdf
- https://cdn.shopify.com/s/files/1/0438/2107/2541/files/bhaskar_the_rascal_songs_free_320kbps.pdf
- https://cdf3feb1-b324-43d7-a4d0-f7dd28882322.filesusr.com/ugd/cf9ff1_806147fc716d4cb8a972611a5846f182.pdf?index=true
- https://ee7d70c6-29cc-4bcd-bacd-a86b8156c615.filesusr.com/ugd/23a6c3_0f405eefb120490c9ac5b0322d2fb275.pdf?index=true
- https://1574f212-300e-4685-bd59-e20f957c075d.filesusr.com/ugd/ea2c45_b65314d63d624a1d830e11ad844af54d.pdf?index=true
- https://98b9eee3-2883-40f5-b8bb-1ba5cc1fbbb3.filesusr.com/ugd/55f640_f51c5d3ba3144c4aa3992931933c42c4.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.club
- files.peterrichardsart.com
- files.primalfitnessleague.com
- gajoru.rstne.com
- cdn.shopify.com
- cdf3feb1-b324-43d7-a4d0-f7dd28882322.filesusr.com
- ee7d70c6-29cc-4bcd-bacd-a86b8156c615.filesusr.com
- 1574f212-300e-4685-bd59-e20f957c075d.filesusr.com
- 98b9eee3-2883-40f5-b8bb-1ba5cc1fbbb3.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report