MALICIOUS — 1be480_0df0e6a0d4f2449aacd76bacee07ddc6.pdf
MALICIOUS — 1be480_0df0e6a0d4f2449aacd76bacee07ddc6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
047f6411da056bb4803d2bf50b2b2f9cdb0a705ed3e3c5baf862db06bc466205 - SHA-1:
a93bfe62600375eca6d8a9125c196aadde453388 - MD5:
09d87c78819e65592c9ffd554e6a78fc - ssdeep:
768:YgGzpDA6YSXVnpDBQLkMAIU2kxDUxQhUuPmIcoRtJ/E:1GFM678LAIGoUR+CRt1E - TLSH:
T1C8307DF31097ED8C76868F03BEAA151D6549EBC960329625499D3A6CC5BC3BC7F00A21 - Submitted as: 1be480_0df0e6a0d4f2449aacd76bacee07ddc6.pdf
- File type: pdf · Size: 36505 bytes
- Verdict: malicious (88/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.PDF.Agent.gen (rule
HEUR:Trojan.PDF.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.cc/wix?keyword=traction+gino+wickman+pdf+download, https://cdn.shopify.com/s/files/1/0470/9954/3702/files/movie_counter_full_movie_free.pdf, https://cdn.shopify.com/s/files/1/0428/4959/9651/files/kekaxekilezulifogow.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/wix?keyword=traction+gino+wickman+pdf+download
- https://cdn.shopify.com/s/files/1/0470/9954/3702/files/movie_counter_full_movie_free.pdf
- https://cdn.shopify.com/s/files/1/0428/4959/9651/files/kekaxekilezulifogow.pdf
- https://cdn.shopify.com/s/files/1/0428/5631/7091/files/best_android_phone_video_games.pdf
- https://cdn.shopify.com/s/files/1/0431/4978/7285/files/22587533445.pdf
- https://cdn.shopify.com/s/files/1/0439/7711/3758/files/aspirated_and_unaspirated_sounds_in.pdf
- https://90e73530-697a-4d69-bc73-991a04ed4f84.filesusr.com/ugd/3be48b_af3adf347b9c400bbe38893025c9b89c.pdf?index=true
- https://370656d3-a856-40a1-be7c-dfb4ba48ea90.filesusr.com/ugd/5b1e3c_caae45fd377d4f57af590eeabad2f22b.pdf?index=true
- https://d34aca10-01e6-4fcd-83c0-02ed3069b390.filesusr.com/ugd/c722c2_cbb553c806d24e45abca51c4e7e4620f.pdf?index=true
- https://34f6bf16-8963-4b25-81a2-f3064dad8aa0.filesusr.com/ugd/c4b402_6ebb5e8dfd514a3e9768f2f95faf1407.pdf?index=true
- https://3213a44a-acff-4c27-94e6-19e2c8261474.filesusr.com/ugd/ea2f88_2ff28e2684074d25b50da472acc63d09.pdf?index=true
- https://8027b46f-92b3-4e4c-906e-8031208d3da9.filesusr.com/ugd/268ab1_9e3989508673492694996d78c5c34fe9.pdf?index=true
- https://621b92cd-25d6-4c45-8da8-5f526998d485.filesusr.com/ugd/99965f_bcaa42d39062410a9cfe3f52fa6965fa.pdf?index=true
- https://95e5dd07-7d53-4717-861b-f720c4992ad5.filesusr.com/ugd/bdc04d_b27e1a2cf8f1443db6d04ab3d59fb79b.pdf?index=true
- https://3b1e6c04-7fe6-4871-ba8b-c96d3c0c4bb9.filesusr.com/ugd/2813e2_be26c7cc29c3482c91da90fafe1028c2.pdf?index=true
- https://0f3751d9-438a-4eca-bea0-7bc2d995a29d.filesusr.com/ugd/0010c8_640aa71461af435f8b1ade7825c2bcf5.pdf?index=true
- https://966ce6f6-95e4-437d-abb9-263d1b52457c.filesusr.com/ugd/cacfd7_bae48fa529134866b6a031fb5081925e.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.cc
- cdn.shopify.com
- 90e73530-697a-4d69-bc73-991a04ed4f84.filesusr.com
- 370656d3-a856-40a1-be7c-dfb4ba48ea90.filesusr.com
- d34aca10-01e6-4fcd-83c0-02ed3069b390.filesusr.com
- 34f6bf16-8963-4b25-81a2-f3064dad8aa0.filesusr.com
- 3213a44a-acff-4c27-94e6-19e2c8261474.filesusr.com
- 8027b46f-92b3-4e4c-906e-8031208d3da9.filesusr.com
- 621b92cd-25d6-4c45-8da8-5f526998d485.filesusr.com
- 95e5dd07-7d53-4717-861b-f720c4992ad5.filesusr.com
- 3b1e6c04-7fe6-4871-ba8b-c96d3c0c4bb9.filesusr.com
- 0f3751d9-438a-4eca-bea0-7bc2d995a29d.filesusr.com
- 966ce6f6-95e4-437d-abb9-263d1b52457c.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report