MALICIOUS — 90661f_f026bf067b844060891f31986312a635.pdf
MALICIOUS — 90661f_f026bf067b844060891f31986312a635.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
625aa4921dcb25cf8bb372c425c5fde0a7a23adcb954c2f98b8ae6043a6f071c - SHA-1:
dd16dca7ad4dfc6791ec2f61ff417fae4565d1ee - MD5:
da90a0811e1eef38690f6fcf56fd6d2b - ssdeep:
768:ogGzpDqJK2O5nNis+rfSKq1Jyfjo7NHuSLInba44ZYr8bcG:lGFOoa6XCo79dLaa4oYwbcG - TLSH:
T1F32F7CF31497ED8CBA87DB039DAB25595186C7486133E760989D7B6DC4BC2BC2E40C60 - Submitted as: 90661f_f026bf067b844060891f31986312a635.pdf
- File type: pdf · Size: 34260 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.PDF.Agent.gen (rule
HEUR:Trojan.PDF.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.me/wix?keyword=assassin%2527s+creed+apk+download+softonic, http://rowufa.unrefined29.com/uploads/1/3/1/4/131406687/kixebefot-towoso-lonezovabigoxov.pdf, http://files.geopoliticaltribune.co.uk/uploads/1/3/0/9/130969873/luraxam.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/wix?keyword=assassin%2527s+creed+apk+download+softonic
- http://rowufa.unrefined29.com/uploads/1/3/1/4/131406687/kixebefot-towoso-lonezovabigoxov.pdf
- http://files.geopoliticaltribune.co.uk/uploads/1/3/0/9/130969873/luraxam.pdf
- http://xujebevur.craigdeebank.com/uploads/1/3/0/8/130814328/farelunuga.pdf
- http://files.ryanstandish.com/uploads/1/3/1/4/131482853/wipuvimede.pdf
- http://ligefe.artscapewynyard.com/uploads/1/3/0/7/130738955/siluvuluzijuj_senimupunaro_kavodufitixow_moriruk.pdf
- http://files.edible-s.com/uploads/1/3/1/0/131070872/sorivejutuj_doseluvelewoza_podil.pdf
- http://files.astronumerologywisdom.com/uploads/1/3/1/3/131380942/zekelake_kazagagedaka.pdf
- https://2face9ff-ecbd-410c-a2c4-e815a4238663.filesusr.com/ugd/4cf28d_597ae7ca6b9c47e1a08292d9e6e416d4.pdf?index=true
- https://46647d56-b2c6-415c-907e-cd01b80dc042.filesusr.com/ugd/f80014_68b861bed6e64ed4a601ad515f87f712.pdf?index=true
- https://f3362f67-267f-457d-bda8-f3a8d04fe7df.filesusr.com/ugd/c638b7_53f33df595d64a16ab7c3319ec446dc5.pdf?index=true
- https://e0417292-3e14-41e7-b614-2aa3b996ebaf.filesusr.com/ugd/76de1a_c05edc7c39f44ddea026cae667e45fa3.pdf?index=true
- https://cdn.shopify.com/s/files/1/0433/9338/4599/files/80706935399.pdf
- https://cdn.shopify.com/s/files/1/0432/8574/1724/files/87725927271.pdf
- https://cdn.shopify.com/s/files/1/0431/5742/2229/files/lumafazivokoguvax.pdf
- https://cdn.shopify.com/s/files/1/0432/7155/3189/files/397137674.pdf
- https://cdn.shopify.com/s/files/1/0432/1103/0683/files/46961466833.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.me
- rowufa.unrefined29.com
- files.geopoliticaltribune.co.uk
- xujebevur.craigdeebank.com
- files.ryanstandish.com
- ligefe.artscapewynyard.com
- files.edible-s.com
- files.astronumerologywisdom.com
- 2face9ff-ecbd-410c-a2c4-e815a4238663.filesusr.com
- 46647d56-b2c6-415c-907e-cd01b80dc042.filesusr.com
- f3362f67-267f-457d-bda8-f3a8d04fe7df.filesusr.com
- e0417292-3e14-41e7-b614-2aa3b996ebaf.filesusr.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report