MALICIOUS — d1c05f_1bfa1cd65ff746d884b7d175c5739821.pdf
MALICIOUS — d1c05f_1bfa1cd65ff746d884b7d175c5739821.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
521e5692bb33a8c25391dbc8ebee0ddd246e783a7ad74abf04fd85fc35a3888b - SHA-1:
fe0330ae07af636c532d73b7d1f5296d02727051 - MD5:
7209b54b6e20028a17231286166ae37f - ssdeep:
768:fgGzpDzRSm+c9D4LqMJ1XcvoktFJJiIZDm7CZbQLp3BFkU:oGFfH+xuA1svXtL7mGhqp3BFkU - TLSH:
T1CF339EF310A7DCCC35AB9F03AFE920695149D6896032A63451D87B3CC4BC2BD6F41A61 - Submitted as: d1c05f_1bfa1cd65ff746d884b7d175c5739821.pdf
- File type: pdf · Size: 49275 bytes
- Verdict: malicious (88/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.com/wix?keyword=managing+anger+with+cbt+for+dummies+pdf, https://c2af496b-23ca-4f77-8911-43bac8d1049d.filesusr.com/ugd/89064d_9baddf8010364cd39f2fe169879f5865.pdf?index=true, https://cd807b47-f4c9-4cd2-8eaa-bbca02502f71.filesusr.com/ugd/8bf3fc_438af720ccde42aba4d2def5164e8e03.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/wix?keyword=managing+anger+with+cbt+for+dummies+pdf
- https://c2af496b-23ca-4f77-8911-43bac8d1049d.filesusr.com/ugd/89064d_9baddf8010364cd39f2fe169879f5865.pdf?index=true
- https://cd807b47-f4c9-4cd2-8eaa-bbca02502f71.filesusr.com/ugd/8bf3fc_438af720ccde42aba4d2def5164e8e03.pdf?index=true
- https://9a91f8d0-6850-4cfa-abd8-717685bdc647.filesusr.com/ugd/8db125_0f6be6be1a304226883ead7dc4e230f5.pdf?index=true
- https://1637c2ce-2b6e-43f0-9153-903a86efd820.filesusr.com/ugd/89064d_3cc4a6767bbe4cac9dbfac4ba199f34f.pdf?index=true
- https://b6346132-eb87-4307-9f45-fde248d5e192.filesusr.com/ugd/8a4248_c0ddafa659674ef08d0a8a30108ac285.pdf?index=true
- http://files.wellnessroadmassage.com/uploads/1/3/0/8/130874250/ponarufem_dilewakiwinedax_jamafevefodeze_mojudipogog.pdf
- http://files.doublebeehoney.com/uploads/1/3/1/3/131384777/tasekuf.pdf
- http://parexe.oteromuseum.org/uploads/1/3/1/8/131871871/fibuf.pdf
- http://files.gcgreenschoolrecert.com/uploads/1/3/1/8/131856415/1373608.pdf
- http://bojoven.ektherapy.com/uploads/1/3/0/8/130814088/xekofowejejorutuzi.pdf
- http://files.u3abroadbeach.com/uploads/1/3/1/4/131483337/berubikojajabeg-nusogagogiloru-nuboga.pdf
- http://files.themanimalchronicles.com/uploads/1/3/1/3/131381540/0b890e668b.pdf
- https://e3642aa2-1777-4bd9-aff1-5a3863e4d85d.filesusr.com/ugd/1acd69_01d3db06c01946cf94ab7eb520f17e63.pdf?index=true
- https://684f2967-68c0-47e8-8385-0414401560a0.filesusr.com/ugd/031dda_074db1f2082f43c69ea25643ff7390d6.pdf?index=true
- https://e87aaae6-ada9-491d-928b-a92409047ba7.filesusr.com/ugd/f1780b_97b12479da8244f1b885518c8403c1cd.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- c2af496b-23ca-4f77-8911-43bac8d1049d.filesusr.com
- cd807b47-f4c9-4cd2-8eaa-bbca02502f71.filesusr.com
- 9a91f8d0-6850-4cfa-abd8-717685bdc647.filesusr.com
- 1637c2ce-2b6e-43f0-9153-903a86efd820.filesusr.com
- b6346132-eb87-4307-9f45-fde248d5e192.filesusr.com
- files.wellnessroadmassage.com
- files.doublebeehoney.com
- parexe.oteromuseum.org
- files.gcgreenschoolrecert.com
- bojoven.ektherapy.com
- files.u3abroadbeach.com
- files.themanimalchronicles.com
- e3642aa2-1777-4bd9-aff1-5a3863e4d85d.filesusr.com
- 684f2967-68c0-47e8-8385-0414401560a0.filesusr.com
- e87aaae6-ada9-491d-928b-a92409047ba7.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report