MALICIOUS — f65518_92d807cb7929451ebec8f36cb2072efb.pdf
MALICIOUS — f65518_92d807cb7929451ebec8f36cb2072efb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
314f9923f6ac77c4561fca9fbc1c7d082ee65e4984fa05b70c39a3c49dbb3292 - SHA-1:
ab6571ac0230e6a29ea5631454867dd7568da229 - MD5:
f3bb37256cfb2c6903fa2969129357de - ssdeep:
768:RgGzpDyDPYz6iLTsBipph70+zMP2fHw1dm0Vl83zw9lV8:iGFmCH9pH70+zA241Vl4zw9z8 - TLSH:
T12B319EF31197EC8CBA8AAF439BA611586086C38D70336A6458CC3B7CC57C6FD6E11961 - Submitted as: f65518_92d807cb7929451ebec8f36cb2072efb.pdf
- File type: pdf · Size: 40304 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.link/wix?keyword=books+never+written+answer+key+page+88, http://files.denaliarts-glassstudio.com/uploads/1/3/0/7/130775402/vamisudoxip.pdf, http://tavavezo.dagninoiv.org/uploads/1/3/1/1/131164211/mifitewegamejem.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/wix?keyword=books+never+written+answer+key+page+88
- http://files.denaliarts-glassstudio.com/uploads/1/3/0/7/130775402/vamisudoxip.pdf
- http://tavavezo.dagninoiv.org/uploads/1/3/1/1/131164211/mifitewegamejem.pdf
- http://files.covidhelp4highland.org/uploads/1/3/1/3/131383386/7145712.pdf
- https://cdn.shopify.com/s/files/1/0481/4661/2373/files/vomiwobijixilajafo.pdf
- https://98c8f798-d4d5-4ed6-a4f4-040ee5bad0e8.filesusr.com/ugd/9117e0_458718c3079b4d9abb9216dcf6ef3986.pdf?index=true
- https://81d6232b-7d35-4b80-b076-16055770a2d5.filesusr.com/ugd/229b11_6937ea822f524db7b528adc4ee6f3f5a.pdf?index=true
- https://23b9a6b3-c462-47be-b906-06abb0e0680a.filesusr.com/ugd/eb6612_58ee550356a04436a9444552a7f2ddf1.pdf?index=true
- https://1da92464-f141-45df-ada1-895977d38edf.filesusr.com/ugd/3eed2b_eb369cfa780e4470bc7306448b16bf8f.pdf?index=true
- https://a11c26be-7631-4f6e-a441-d1e4b8dfc5c4.filesusr.com/ugd/5de1df_1bfcabaa07af464a83bffa6c8f01ce1d.pdf?index=true
- https://e7f1b13f-784f-47d2-96b9-5d7987e796f0.filesusr.com/ugd/0cd3a8_55d8b7d42cfd4fafbbbfac3734b7d1ed.pdf?index=true
- https://4fa2bd28-b75e-4728-b2a5-6f77f2d95e1d.filesusr.com/ugd/008e52_1cda9c7966134c26a5b46b5262c5ed0b.pdf?index=true
- https://5d33a5fe-9623-459e-84a9-d982b2d3b952.filesusr.com/ugd/3225da_6979b89ff6ce470c86b9342039475b7b.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.link
- files.denaliarts-glassstudio.com
- tavavezo.dagninoiv.org
- files.covidhelp4highland.org
- cdn.shopify.com
- 98c8f798-d4d5-4ed6-a4f4-040ee5bad0e8.filesusr.com
- 81d6232b-7d35-4b80-b076-16055770a2d5.filesusr.com
- 23b9a6b3-c462-47be-b906-06abb0e0680a.filesusr.com
- 1da92464-f141-45df-ada1-895977d38edf.filesusr.com
- a11c26be-7631-4f6e-a441-d1e4b8dfc5c4.filesusr.com
- e7f1b13f-784f-47d2-96b9-5d7987e796f0.filesusr.com
- 4fa2bd28-b75e-4728-b2a5-6f77f2d95e1d.filesusr.com
- 5d33a5fe-9623-459e-84a9-d982b2d3b952.filesusr.com
- kd.au
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report