MALICIOUS — 7a13df_ee4be3df8642429d9464d47bd9a6d9e0.pdf
MALICIOUS — 7a13df_ee4be3df8642429d9464d47bd9a6d9e0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (78/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
41d1b98578e8059d50689ed965c27a82bf202d0ae53120bfb305888caef620f2 - SHA-1:
eba9215603f5cb361d890d761faa8605e6eb8d07 - MD5:
6f303b741b5cb41c3c71326cde9f474d - ssdeep:
768:JgGzpDrvx81BviEEu3LUVAXnJFRy0QPMpWy0XG+UhCfKxNYQHs5K+/px9p2C:qGF3vxS7Ry0QPJy0WZ0KxNZU1H9pp - TLSH:
T12132AEF344A7ED8D29C79B132CAA2089A584E78C3137AA6118D8772CD5BC1BDBF10571 - Submitted as: 7a13df_ee4be3df8642429d9464d47bd9a6d9e0.pdf
- File type: pdf · Size: 45097 bytes
- Verdict: malicious (78/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 78/100 is the fusion of 5 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.link/wix?keyword=hungry+howies+job+application+pdf, https://cdn.shopify.com/s/files/1/0461/9170/6263/files/26653379678.pdf, https://cdn.shopify.com/s/files/1/0431/8937/1029/files/moxatogozipekozixiginij.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/wix?keyword=hungry+howies+job+application+pdf
- https://cdn.shopify.com/s/files/1/0461/9170/6263/files/26653379678.pdf
- https://cdn.shopify.com/s/files/1/0431/8937/1029/files/moxatogozipekozixiginij.pdf
- https://cdn.shopify.com/s/files/1/0461/5539/9331/files/27650207534.pdf
- https://cdn.shopify.com/s/files/1/0434/1936/9639/files/bloom_s_taxonomy_of_objectives.pdf
- https://cdn.shopify.com/s/files/1/0437/7303/4657/files/nozovip.pdf
- https://d4a857f0-50fe-4290-9ece-c50689951518.filesusr.com/ugd/8d0191_1ff2090b9b2f40368e174598f6b0d12f.pdf?index=true
- https://554298ff-9afe-4c1f-a897-c4d3232f8835.filesusr.com/ugd/99965f_fc2ee29a690e4d469ac60be681dc9e99.pdf?index=true
- https://bed63f1c-0916-4ebd-b48a-7e4cf2702ce4.filesusr.com/ugd/2d1648_fa1213ce76d04190a435d9779be13e31.pdf?index=true
- https://d53bb6af-6d57-474a-b6a4-f13b8172a7ad.filesusr.com/ugd/8e6e76_a658a5c3aa2c4e4b84892c884f1efe35.pdf?index=true
- https://6248e019-fc53-4c29-aab7-3058998060d8.filesusr.com/ugd/51c472_fde06d7b8cb5461e9ace238d80b758ef.pdf?index=true
- https://cdn.shopify.com/s/files/1/0440/0221/4046/files/address_book_template_html.pdf
- https://cdn.shopify.com/s/files/1/0437/7218/2685/files/8154192114.pdf
- https://cdn.shopify.com/s/files/1/0436/5438/1721/files/cake_making_game_free_for_pc.pdf
- https://cdn.shopify.com/s/files/1/0437/7785/1550/files/avastar_free_2015.pdf
- https://cdn.shopify.com/s/files/1/0433/1637/9816/files/solukoranejepew.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.link
- cdn.shopify.com
- d4a857f0-50fe-4290-9ece-c50689951518.filesusr.com
- 554298ff-9afe-4c1f-a897-c4d3232f8835.filesusr.com
- bed63f1c-0916-4ebd-b48a-7e4cf2702ce4.filesusr.com
- d53bb6af-6d57-474a-b6a4-f13b8172a7ad.filesusr.com
- 6248e019-fc53-4c29-aab7-3058998060d8.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report