MALICIOUS — 724fb5_1f3b93294364420787e712b76af5e819.pdf
MALICIOUS — 724fb5_1f3b93294364420787e712b76af5e819.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
4b365e8406ceac2ecd6a579f0734f36942c5ec73a57a5c6e68f6bf5d539dace2 - SHA-1:
529a4ff2f374fde97df8b5f825e983ca69f0c0bd - MD5:
6ed1cbf38340247217eab989832ff360 - ssdeep:
1536:6GFslSpxjcOxTCZyY0Q4MHeUXN4F8JQ2NJRiji4x9W+:jFswpxjcOZAN0MfXOztO4W+ - TLSH:
T10836D0F3459AEC4C69D68F23ADA91419A585C38C61B3E7B05899327CD07C2FD6E80A31 - Submitted as: 724fb5_1f3b93294364420787e712b76af5e819.pdf
- File type: pdf · Size: 69370 bytes
- Verdict: malicious (88/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.club/wix?keyword=element+43+smart+tv+manual, https://cdn.shopify.com/s/files/1/0437/3191/0821/files/haryana_bjp_candidate_list.pdf, https://cdn.shopify.com/s/files/1/0431/2442/4853/files/web_design_proposal_template_free.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/wix?keyword=element+43+smart+tv+manual
- https://cdn.shopify.com/s/files/1/0437/3191/0821/files/haryana_bjp_candidate_list.pdf
- https://cdn.shopify.com/s/files/1/0431/2442/4853/files/web_design_proposal_template_free.pdf
- https://cdn.shopify.com/s/files/1/0434/5964/1496/files/13106878577.pdf
- https://cdn.shopify.com/s/files/1/0437/3096/0549/files/1759429459.pdf
- http://files.openmindimprov.com/uploads/1/3/0/7/130776611/4f7740.pdf
- http://mowejo.vexsens.com/uploads/1/3/0/7/130775195/042d16.pdf
- http://povixegu.borderproud.com/uploads/1/3/1/3/131384169/filugigomaxav-jewimuwujatogo-rukegedixa.pdf
- https://ee266eaf-422d-48dc-be6d-9ffd4744f7ad.filesusr.com/ugd/c57cae_8ae9156c61c94b8197a74a2b82f8d7df.pdf?index=true
- https://ffc62988-6def-41ed-9e56-8b26cc4a3500.filesusr.com/ugd/3225da_4c6fde3126bf45c6b3f17e3b18471d38.pdf?index=true
- https://33ee220e-e6c2-437a-a2dc-879221639591.filesusr.com/ugd/f68081_cc2d8bed6a3841808e8ddc82c688969f.pdf?index=true
- https://ce4c9986-8d0f-4380-8440-b8f076f23c2a.filesusr.com/ugd/dcf311_98eb7c3d362c4fadb58f8ae2d7726274.pdf?index=true
- https://44755a71-10c3-48d7-84a6-40d39a4542df.filesusr.com/ugd/f6336d_8bd0d8bfa0324350b9d8713ce92ab536.pdf?index=true
- https://086939ca-4bfe-4bc8-b57f-0f19a6d2b396.filesusr.com/ugd/035627_c0b00e33bf45464098dbd0cbc509a4e5.pdf?index=true
- https://99113d02-f020-4b5d-945d-7fc3eb0a0f33.filesusr.com/ugd/b9801a_1f3254bf977048da8755f38add60a059.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.club
- cdn.shopify.com
- files.openmindimprov.com
- mowejo.vexsens.com
- povixegu.borderproud.com
- ee266eaf-422d-48dc-be6d-9ffd4744f7ad.filesusr.com
- ffc62988-6def-41ed-9e56-8b26cc4a3500.filesusr.com
- 33ee220e-e6c2-437a-a2dc-879221639591.filesusr.com
- ce4c9986-8d0f-4380-8440-b8f076f23c2a.filesusr.com
- 44755a71-10c3-48d7-84a6-40d39a4542df.filesusr.com
- 086939ca-4bfe-4bc8-b57f-0f19a6d2b396.filesusr.com
- 99113d02-f020-4b5d-945d-7fc3eb0a0f33.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report