MALICIOUS — 60ffa2_212ce107b59748dc8d147caae452ffbc.pdf
MALICIOUS — 60ffa2_212ce107b59748dc8d147caae452ffbc.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
10ee5c40972a1a994e15f9c3e6df964df79d3802ad9097ecb6933e1775180ffc - SHA-1:
5b4bf6295012bf6de2cd6281ceb8556ec2de23cf - MD5:
0290e1fbad8245beb15bda145977fdb7 - ssdeep:
768:FgGzpDH4AHxF1Dz31drT2cUdWJo3FpHzqnkxoUnrVJ:WGFL4AKcOWqPTskyqrVJ - TLSH:
T17531BEF3506BED8C6EC6AF039DAA0148114AC3896132AA704D9D3F7DC57C6FCAE44961 - Submitted as: 60ffa2_212ce107b59748dc8d147caae452ffbc.pdf
- File type: pdf · Size: 40421 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.me/wix?keyword=gifted+hands+chapter+14+summary, https://e4e06f3b-4d4d-4a12-a091-6caaf84afef4.filesusr.com/ugd/cc3ca9_f19dfec970214b6eaea276670c9cdcd3.pdf?index=true, https://89f2621d-84cd-4e86-bef2-65d684c4dda2.filesusr.com/ugd/904a8b_f29e1fd462e74d549e7176a6d3cced7d.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/wix?keyword=gifted+hands+chapter+14+summary
- https://e4e06f3b-4d4d-4a12-a091-6caaf84afef4.filesusr.com/ugd/cc3ca9_f19dfec970214b6eaea276670c9cdcd3.pdf?index=true
- https://89f2621d-84cd-4e86-bef2-65d684c4dda2.filesusr.com/ugd/904a8b_f29e1fd462e74d549e7176a6d3cced7d.pdf?index=true
- https://625011a4-6eb7-485f-8988-c2eb84890c9e.filesusr.com/ugd/8c5bc8_e2b341435fef4fe788c570a56bc5c15a.pdf?index=true
- https://22d8ba10-bfa7-427b-9a2e-d8f736473fd7.filesusr.com/ugd/b56239_b07bf4cf65dc449dab617814d7d584d8.pdf?index=true
- https://cdn.shopify.com/s/files/1/0428/6965/3663/files/lazijet.pdf
- http://files.carlsoncattlecompany.com/uploads/1/3/0/8/130874253/700861.pdf
- http://tazipexod.jenniferhalli.com/uploads/1/3/1/4/131483830/durer.pdf
- https://cdn.shopify.com/s/files/1/0430/0115/1651/files/dikolikenizavon.pdf
- https://cdn.shopify.com/s/files/1/0438/1920/4765/files/bumovafumuz.pdf
- https://cdn.shopify.com/s/files/1/0429/1801/9235/files/41787940725.pdf
- https://cdn.shopify.com/s/files/1/0435/6099/2927/files/libro_autometrica_2020.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.me
- e4e06f3b-4d4d-4a12-a091-6caaf84afef4.filesusr.com
- 89f2621d-84cd-4e86-bef2-65d684c4dda2.filesusr.com
- 625011a4-6eb7-485f-8988-c2eb84890c9e.filesusr.com
- 22d8ba10-bfa7-427b-9a2e-d8f736473fd7.filesusr.com
- cdn.shopify.com
- files.carlsoncattlecompany.com
- tazipexod.jenniferhalli.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report