MALICIOUS — 008e52_8421e420cad84967955a127f91bd8e92.pdf
MALICIOUS — 008e52_8421e420cad84967955a127f91bd8e92.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
689d37c00de4f12619caf75385d60a1a0c7344c2711ec7c1fc7207709e31ea73 - SHA-1:
c7c0f9b5407a78484f7e42ee9ed370e83e6f5bb7 - MD5:
09b0b14c0e8d50efa7b13b4796c8ffa4 - ssdeep:
768:EgGzpDJhNtxKw/x7DjUORmpAv43H6MJOpfg44AYYZufBBsqgCf:xGFVRxKw/x7/xPA3H6jYHuZ6BiqgCf - TLSH:
T15731AEF31097EE8C3E8A9F03EDAA1098509AD7C8302797B41499776DD57C6BDAE40870 - Submitted as: 008e52_8421e420cad84967955a127f91bd8e92.pdf
- File type: pdf · Size: 42434 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=mr+coffee+espresso+maker+instruction+manual, http://betaxipeb.thedpgp.com/uploads/1/3/0/8/130874493/c2b8b.pdf, http://files.trinidadcf.org/uploads/1/3/0/7/130776673/delibizozomuxi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/wix?keyword=mr+coffee+espresso+maker+instruction+manual
- http://betaxipeb.thedpgp.com/uploads/1/3/0/8/130874493/c2b8b.pdf
- http://files.trinidadcf.org/uploads/1/3/0/7/130776673/delibizozomuxi.pdf
- http://fasurebi.silkroadrebellion.com/uploads/1/3/2/6/132682924/4a14f13b0.pdf
- http://files.angusyoungroofing.co.uk/uploads/1/3/1/3/131382673/xotupopiwowame-gexuro.pdf
- http://files.mollysteinwald.org/uploads/1/3/0/8/130873822/tiduloregidase-porig-zuzitiv.pdf
- https://a967195c-9d29-430f-a36c-f102bbd184d5.filesusr.com/ugd/03f576_1a3bd150831444f3ad6dd086d93322fa.pdf?index=true
- https://e3682938-c9fa-48db-95ed-a8e835a33605.filesusr.com/ugd/0d018b_fbe38ed326204f7189520173b6c5e29e.pdf?index=true
- https://1c30081c-fed9-40f8-966f-0be0027cbbe3.filesusr.com/ugd/1715bf_5b33d78b6b95494584973cdceafb5981.pdf?index=true
- https://1e50fb73-5bfc-4366-a9e1-9336b908f7ad.filesusr.com/ugd/6cabbb_cf4345b54a7640178b536d7d48bef783.pdf?index=true
- https://7cba7fb1-1f96-4f30-9d7c-460a6e6cec2d.filesusr.com/ugd/ee9d3f_c3722f9dafeb46e484e6f8b734908e6b.pdf?index=true
- https://1926c750-463e-4ef1-b1a1-57a0646c4360.filesusr.com/ugd/97aff7_08358923c96544be8d6aa36dd6e8da57.pdf?index=true
- https://e9bd1398-e0a7-435e-a283-7ff3f7cc5f6e.filesusr.com/ugd/957c7b_dceef5ea693748ddb3990d971ece330f.pdf?index=true
- https://be0739a3-2ae0-4208-b55d-bc0d0133d607.filesusr.com/ugd/271e65_68bf8323bb6a47839a6a96cbb35bd192.pdf?index=true
- https://f32a973f-10e4-4da8-98a5-e3be4b29b6ec.filesusr.com/ugd/ee6770_5f239f01a28d4aa39ac46a5ca6bc88f3.pdf?index=true
- https://5c175e41-4448-4871-a73d-2c10225b56f4.filesusr.com/ugd/409ca8_9b84738399824631bf938f53fee4510b.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- betaxipeb.thedpgp.com
- files.trinidadcf.org
- fasurebi.silkroadrebellion.com
- files.angusyoungroofing.co.uk
- files.mollysteinwald.org
- a967195c-9d29-430f-a36c-f102bbd184d5.filesusr.com
- e3682938-c9fa-48db-95ed-a8e835a33605.filesusr.com
- 1c30081c-fed9-40f8-966f-0be0027cbbe3.filesusr.com
- 1e50fb73-5bfc-4366-a9e1-9336b908f7ad.filesusr.com
- 7cba7fb1-1f96-4f30-9d7c-460a6e6cec2d.filesusr.com
- 1926c750-463e-4ef1-b1a1-57a0646c4360.filesusr.com
- e9bd1398-e0a7-435e-a283-7ff3f7cc5f6e.filesusr.com
- be0739a3-2ae0-4208-b55d-bc0d0133d607.filesusr.com
- f32a973f-10e4-4da8-98a5-e3be4b29b6ec.filesusr.com
- 5c175e41-4448-4871-a73d-2c10225b56f4.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report