MALICIOUS — 2f3ac6_a6360de00c1f4e76be939a855233e014.pdf
MALICIOUS — 2f3ac6_a6360de00c1f4e76be939a855233e014.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
0b95e4737135e23a67262250a5605be2ed3eaec251abcbe44e20ec77fda513c5 - SHA-1:
c4a30d3983011db9cb3b55dc090c2d40e7d98de7 - MD5:
58834095e68d9dd819dc1e7bad64b2cb - ssdeep:
768:rgGzpD7Kr7FxQT7wOfE/XdrRdy82FFu6YUO3OtDZhYwbOhW0pp9ODUEeQV:UGFnKPT8BeX5RgYVUO3OrhY3hW2KUEey - TLSH:
T15E33AFF311D7EC8C7B865B17AE971068A186E78DA13396A005DCB76CC47C6EC6F40A21 - Submitted as: 2f3ac6_a6360de00c1f4e76be939a855233e014.pdf
- File type: pdf · Size: 48885 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=pocket+monsters+apk+mod, http://files.wegnerauctioneers.com/uploads/1/3/0/9/130969489/nururiwupunuma.pdf, http://files.parker-co.com/uploads/1/3/1/4/131452903/9376148.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/wix?keyword=pocket+monsters+apk+mod
- http://files.wegnerauctioneers.com/uploads/1/3/0/9/130969489/nururiwupunuma.pdf
- http://files.parker-co.com/uploads/1/3/1/4/131452903/9376148.pdf
- http://files.drifterbrewingsystems.com/uploads/1/3/1/8/131871786/aada01b4ad04dcf.pdf
- http://files.thefrivolousfox.com/uploads/1/3/1/6/131606453/weruba.pdf
- http://files.kenleverart.com/uploads/1/3/1/3/131379252/e96fa84.pdf
- http://files.sundancecrs.com/uploads/1/3/2/6/132681452/7356367.pdf
- http://wajipo.americanuktaxsolutions.com/uploads/1/3/0/9/130969198/c9f2ef9.pdf
- http://files.amiddleagedtraveler.com/uploads/1/3/1/6/131637169/pivemogezif.pdf
- http://files.12monthbeauty.com/uploads/1/3/0/8/130874128/6301925.pdf
- https://8d583be4-6862-4fa4-963e-b1ae5230ebc1.filesusr.com/ugd/93c935_a36fa7c06fa749a68be44b0a32c93bd6.pdf?index=true
- https://f8f9f8df-c702-4c06-827d-07d217209aac.filesusr.com/ugd/b56239_0a50d52d7c7f454cb4a9285c3db371a0.pdf?index=true
- https://5cb73885-7963-4c64-af49-721dc1fe1960.filesusr.com/ugd/10b11f_4a274e0ba6ad444daa9b95bee0e6b848.pdf?index=true
- https://31430127-d193-4619-8f5b-75c4a9df04c6.filesusr.com/ugd/69695d_b2c52c0ae4b64ffe899f9ae52c8f7e5b.pdf?index=true
- https://b5226844-37ce-4630-b4fd-68885e627fdc.filesusr.com/ugd/a13bc2_a5cbf2ce95d243f5ba33374070f7d52d.pdf?index=true
- https://3f0ce0ad-40c1-486a-a761-caf5bbd93376.filesusr.com/ugd/bdc04d_1248e58080f248d39170eb6897e66098.pdf?index=true
- https://dbeb6247-ffb3-4961-9c40-511ef4e0d3b5.filesusr.com/ugd/8a9bcc_07cdf464aa0d4dec83944655940385d4.pdf?index=true
- https://df48b4b0-ae2e-40e5-9842-6fd1ebe4adb4.filesusr.com/ugd/cc3ca9_746cf991d7154938b5bd902f167f8e71.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- files.wegnerauctioneers.com
- files.parker-co.com
- files.drifterbrewingsystems.com
- files.thefrivolousfox.com
- files.kenleverart.com
- files.sundancecrs.com
- wajipo.americanuktaxsolutions.com
- files.amiddleagedtraveler.com
- files.12monthbeauty.com
- 8d583be4-6862-4fa4-963e-b1ae5230ebc1.filesusr.com
- f8f9f8df-c702-4c06-827d-07d217209aac.filesusr.com
- 5cb73885-7963-4c64-af49-721dc1fe1960.filesusr.com
- 31430127-d193-4619-8f5b-75c4a9df04c6.filesusr.com
- b5226844-37ce-4630-b4fd-68885e627fdc.filesusr.com
- 3f0ce0ad-40c1-486a-a761-caf5bbd93376.filesusr.com
- dbeb6247-ffb3-4961-9c40-511ef4e0d3b5.filesusr.com
- df48b4b0-ae2e-40e5-9842-6fd1ebe4adb4.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report