MALICIOUS — b56239_80c45ee581da44139ee44361271c4953.pdf
MALICIOUS — b56239_80c45ee581da44139ee44361271c4953.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (78/100). 2 of 54 detection engines flagged it.
Identification
- SHA-256:
4a27bbc684d03c00bc154e2f32dc0f17074a8a82846486e6654d2d46553ecfff - SHA-1:
08004cf5b30806bc981c2a69d38096b0e6515a0f - MD5:
fcfdea7329e9eae74c63e009a807b427 - ssdeep:
768:yggGzpDYrNvhx+5Y9gYM4XbGf/b1QYebGMg/NEERHPhIodCf5:GGFUNGf/b1QbbGxWERv6UCf5 - TLSH:
T17531AEF3902BDC4D76CAEF13AEA6144EB045CA896032A1B408D9777DC4B83BC6D50A71 - Submitted as: b56239_80c45ee581da44139ee44361271c4953.pdf
- File type: pdf · Size: 40930 bytes
- Verdict: malicious (78/100)
Detections (2 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 78/100 is the fusion of 5 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.me/wix?keyword=assassin%2527s+creed+identity+android+apk, https://e13a8b0f-cdbb-4ea6-8e26-413b335614fc.filesusr.com/ugd/5ea691_963c9421f94540feb0d1c2b7950de757.pdf?index=true, https://3d87419a-8e71-46ef-a8c9-d887ae51aa0a.filesusr.com/ugd/70e7d4_a5df0ad1285c418cb658611f8926a766.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/wix?keyword=assassin%2527s+creed+identity+android+apk
- https://e13a8b0f-cdbb-4ea6-8e26-413b335614fc.filesusr.com/ugd/5ea691_963c9421f94540feb0d1c2b7950de757.pdf?index=true
- https://3d87419a-8e71-46ef-a8c9-d887ae51aa0a.filesusr.com/ugd/70e7d4_a5df0ad1285c418cb658611f8926a766.pdf?index=true
- https://586e8a90-0d0a-4c97-8b13-97902f2516b0.filesusr.com/ugd/49f5ef_dec61db6ed054ff894322309400609d5.pdf?index=true
- https://812bca8f-8894-4a7e-85eb-d7dcde6a3015.filesusr.com/ugd/c57cae_788cce77602d447881ffef8b5cba5129.pdf?index=true
- https://cdn.shopify.com/s/files/1/0466/2552/1829/files/17875747448.pdf
- https://cdn.shopify.com/s/files/1/0435/5801/1035/files/dikutoma.pdf
- https://cdn.shopify.com/s/files/1/0430/1992/7713/files/89437570509.pdf
- https://cdn.shopify.com/s/files/1/0431/7813/1611/files/65429680412.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/neretidesalefadim.pdf
- https://cdn.shopify.com/s/files/1/0438/2215/3890/files/89326219150.pdf
- https://cdn.shopify.com/s/files/1/0429/9145/2314/files/one_clue_crossword_answers_chapter_15.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/sikotifukiv.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.me
- e13a8b0f-cdbb-4ea6-8e26-413b335614fc.filesusr.com
- 3d87419a-8e71-46ef-a8c9-d887ae51aa0a.filesusr.com
- 586e8a90-0d0a-4c97-8b13-97902f2516b0.filesusr.com
- 812bca8f-8894-4a7e-85eb-d7dcde6a3015.filesusr.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report