MALICIOUS — 33a16d_be4a7420ebb844edbb9d272d2b6b7bca.pdf
MALICIOUS — 33a16d_be4a7420ebb844edbb9d272d2b6b7bca.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (78/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
352feafe855090b5ccbe5b8f50e8bb5eb0b64ac157f0d575e7c5a7d6d0ac5552 - SHA-1:
6aa73ae242127f93f23c64cfd5d1ffe83ad76118 - MD5:
36085e947c580a1b739520f1b0b1e6a6 - ssdeep:
768:ygGzpDhZUxsbn9XLyVHhhFZzLS5WunnG2t3On1rdHtJsc9tG0MEERPtJRx:vGF1ZIFMgeG2t3On95jN9tG0MEERPtJ7 - TLSH:
T1EB329EF310ABED8C7A8A5F937D6711687189D68C2123A6A145CC766CC47C6ECAF40B21 - Submitted as: 33a16d_be4a7420ebb844edbb9d272d2b6b7bca.pdf
- File type: pdf · Size: 46445 bytes
- Verdict: malicious (78/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 78/100 is the fusion of 5 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.com/wix?keyword=act+69a+answer+explanations, https://9e50eb9f-b75a-4c43-a59a-de7b30cb4e3d.filesusr.com/ugd/66f3f9_c5b53b81cfd64b04935bff880b2e4942.pdf?index=true, https://c7d07423-3a66-4e49-8734-204fece736d3.filesusr.com/ugd/3ddeef_0e02a441845148a79e5076b524ef2cfb.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/wix?keyword=act+69a+answer+explanations
- https://9e50eb9f-b75a-4c43-a59a-de7b30cb4e3d.filesusr.com/ugd/66f3f9_c5b53b81cfd64b04935bff880b2e4942.pdf?index=true
- https://c7d07423-3a66-4e49-8734-204fece736d3.filesusr.com/ugd/3ddeef_0e02a441845148a79e5076b524ef2cfb.pdf?index=true
- https://76ce13fa-6817-4dd7-a765-0d69d0ea408c.filesusr.com/ugd/2dbf5a_ba7cc5c4474841caa555e54bd446ac36.pdf?index=true
- https://d856284f-7943-4798-8b2e-e6b4a919d369.filesusr.com/ugd/d4da64_ef65713034cd41cfaaf294f6a193478b.pdf?index=true
- https://fcde3f17-064a-4b36-9df5-b717a8aebbcb.filesusr.com/ugd/60e703_f72799ca2868495d9da75cdfcaf2df7a.pdf?index=true
- https://aafcd906-0ac8-405d-bd82-9cd5ed01be50.filesusr.com/ugd/3ed902_9d05e7e11d6345eb8438b532255d4749.pdf?index=true
- https://9400ae49-5fc5-42f7-8f81-1952de9aad70.filesusr.com/ugd/2eff39_8e35495bc8684190a1dd203fbc582449.pdf?index=true
- https://202b13e1-638c-4623-a389-b6cfab0f936b.filesusr.com/ugd/0d2908_433a5772083842d692a9fb9aabff54a5.pdf?index=true
- https://cdn.shopify.com/s/files/1/0440/5470/8389/files/6131995357.pdf
- https://cdn.shopify.com/s/files/1/0433/4485/5195/files/88157133997.pdf
- https://cdn.shopify.com/s/files/1/0483/0763/4338/files/mcsa_70-740_study_guide.pdf
- https://cdn.shopify.com/s/files/1/0431/2596/4957/files/el_libro_de_los_muertos_egipto_resumen.pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/646255477.pdf
- https://6aee81f9-9814-4661-8ea1-d8b5a9239a34.filesusr.com/ugd/3a38e0_d008703639b84f03aa784e310643d301.pdf?index=true
- https://9ff1e5f7-eaa6-44db-b2a4-82af6c2595d7.filesusr.com/ugd/4b874d_bafc99100d324296b231331692e08fa4.pdf?index=true
- https://c155daed-697d-48fc-8655-aac9334dbb10.filesusr.com/ugd/3ddeef_16523505bbb64ea2949b66e732909b72.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- 9e50eb9f-b75a-4c43-a59a-de7b30cb4e3d.filesusr.com
- c7d07423-3a66-4e49-8734-204fece736d3.filesusr.com
- 76ce13fa-6817-4dd7-a765-0d69d0ea408c.filesusr.com
- d856284f-7943-4798-8b2e-e6b4a919d369.filesusr.com
- fcde3f17-064a-4b36-9df5-b717a8aebbcb.filesusr.com
- aafcd906-0ac8-405d-bd82-9cd5ed01be50.filesusr.com
- 9400ae49-5fc5-42f7-8f81-1952de9aad70.filesusr.com
- 202b13e1-638c-4623-a389-b6cfab0f936b.filesusr.com
- cdn.shopify.com
- 6aee81f9-9814-4661-8ea1-d8b5a9239a34.filesusr.com
- 9ff1e5f7-eaa6-44db-b2a4-82af6c2595d7.filesusr.com
- c155daed-697d-48fc-8655-aac9334dbb10.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report