MALICIOUS — 3be48b_f29be8a9901d413e90ec7c4042c3f776.pdf
MALICIOUS — 3be48b_f29be8a9901d413e90ec7c4042c3f776.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
7540638fb99dc3842284a561d5fbbd8e0dd2c09bd4f972e8d25e21c034e89336 - SHA-1:
00af87c77b0c5e5c17d2b6dd2691f536a67b5712 - MD5:
59746b7718e0c299a0484a8631ddd7f7 - ssdeep:
1536:rGFN8pbZIEMhSQja/kmW1vslMX9PlRj9oQQ6Xr8Nc3ZFk:KFN2CL+kmW1Ely9z9+6Xw63Q - TLSH:
T15234BEF350ABDD8C7A82AB1769E520557019D6CD61339BA024D87B7CC47C3EC2F61A50 - Submitted as: 3be48b_f29be8a9901d413e90ec7c4042c3f776.pdf
- File type: pdf · Size: 52579 bytes
- Verdict: malicious (88/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.link/wix?keyword=words+with+f+in+them+scrabble, http://files.janansiam.com/uploads/1/3/0/7/130739069/ritugixiduwev-xitoxid-pipatasituxur-bivaviw.pdf, http://files.rockywoodlandforge.com/uploads/1/3/0/7/130775393/3255747.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/wix?keyword=words+with+f+in+them+scrabble
- http://files.janansiam.com/uploads/1/3/0/7/130739069/ritugixiduwev-xitoxid-pipatasituxur-bivaviw.pdf
- http://files.rockywoodlandforge.com/uploads/1/3/0/7/130775393/3255747.pdf
- http://sufaxi.takeoffwithtechnique.com/uploads/1/3/0/9/130969186/953430.pdf
- http://bedabi.believenufitness.com/uploads/1/3/1/0/131071157/fapazaxur-wabujuvi.pdf
- https://cdn.shopify.com/s/files/1/0429/8270/3257/files/capitulacion_de_santa_fe.pdf
- https://73ae0315-188d-4244-8b59-153900ab6d91.filesusr.com/ugd/b463f2_28e5663a4e034dc39d952fd66d051664.pdf?index=true
- https://854666fc-9f14-47b9-aa29-c3bee1c5a2a4.filesusr.com/ugd/850f07_0c7a9c754fee4cd9867e2780cb02301d.pdf?index=true
- https://d42417d0-c825-46cb-96b2-294150de5215.filesusr.com/ugd/0e6328_540f067494eb4cb5b1e2306b26767222.pdf?index=true
- https://cfbbcfa7-1491-4d5c-9661-632533ee163f.filesusr.com/ugd/5f226b_3a9605c466ec48ef9b09c43934ca44f4.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.link
- files.janansiam.com
- files.rockywoodlandforge.com
- sufaxi.takeoffwithtechnique.com
- bedabi.believenufitness.com
- cdn.shopify.com
- 73ae0315-188d-4244-8b59-153900ab6d91.filesusr.com
- 854666fc-9f14-47b9-aa29-c3bee1c5a2a4.filesusr.com
- d42417d0-c825-46cb-96b2-294150de5215.filesusr.com
- cfbbcfa7-1491-4d5c-9661-632533ee163f.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report