MALICIOUS — 0cd019_adf4cf8fb04e4289a75d96b618124ff3.pdf
MALICIOUS — 0cd019_adf4cf8fb04e4289a75d96b618124ff3.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (78/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
79f055a2d6227ad2ee2bb6e64f2d3c9a4f5fe18afa8a6de6dbe945c8eade1b5c - SHA-1:
03d5727445d65c3250b83b7db92651d5ff797143 - MD5:
2e5e92f646e8f8af2756517b0aa10d06 - ssdeep:
768:5gGzpDipNZbM/F8jMSVEDgjEH4qz2v9xbsy/WHFi9FMb+:6GFO5M2SgLu2v9h/U6ub+ - TLSH:
T195319EF34147EDCC3A976B176ABA10597186CA8DB126D36059D8763CC87C3EC6E00A61 - Submitted as: 0cd019_adf4cf8fb04e4289a75d96b618124ff3.pdf
- File type: pdf · Size: 40404 bytes
- Verdict: malicious (78/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 78/100 is the fusion of 5 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.me/wix?keyword=rockler+drill+guide, https://cdn.shopify.com/s/files/1/0440/0958/6846/files/89702038448.pdf, https://cdn.shopify.com/s/files/1/0435/8357/0083/files/mikejivi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/wix?keyword=rockler+drill+guide
- https://cdn.shopify.com/s/files/1/0440/0958/6846/files/89702038448.pdf
- https://cdn.shopify.com/s/files/1/0435/8357/0083/files/mikejivi.pdf
- https://cdn.shopify.com/s/files/1/0440/5100/5590/files/46004829391.pdf
- https://cdn.shopify.com/s/files/1/0437/6163/1384/files/adrenalina_neurotransmisor_funcion.pdf
- https://98a35ddc-ae86-452f-935e-aa290bf2b15e.filesusr.com/ugd/d93890_9cdddf1dd24545049fb153ca91e8b085.pdf?index=true
- https://a2ded59c-40e8-4709-8f30-2b241dd0a56c.filesusr.com/ugd/9117e0_e3ce4f312f0c4c2a82b59f399b26f740.pdf?index=true
- https://ffc88da5-60b7-48f6-a8ef-3ad7e0be1845.filesusr.com/ugd/ad2ade_b2255c8e67504b37bc753683ff922dc2.pdf?index=true
- https://148c3382-cd48-4444-a9a0-9f31c451826b.filesusr.com/ugd/29c71c_70c5fce5772541099b9eefcd735a34ee.pdf?index=true
- https://e1eac49a-f6bb-4b00-afc6-1c82b802c344.filesusr.com/ugd/e80f4c_70c5e849fc574bb58921711b9c1aea42.pdf?index=true
- https://c3f03ef5-5d46-427c-b53b-918515100afc.filesusr.com/ugd/61b8bf_cebabe95ab3942ae82b2758b87f24389.pdf?index=true
- https://1ae675fa-6ae0-4b2b-a8b9-44dd507bb590.filesusr.com/ugd/bc0b97_07b5e92dc49a49ee98d32179ea97b816.pdf?index=true
- https://413d6933-354a-4c84-a91a-40189b9a0322.filesusr.com/ugd/dcc11b_011f9c2e872541c0a862c60afe70cf3b.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.me
- cdn.shopify.com
- 98a35ddc-ae86-452f-935e-aa290bf2b15e.filesusr.com
- a2ded59c-40e8-4709-8f30-2b241dd0a56c.filesusr.com
- ffc88da5-60b7-48f6-a8ef-3ad7e0be1845.filesusr.com
- 148c3382-cd48-4444-a9a0-9f31c451826b.filesusr.com
- e1eac49a-f6bb-4b00-afc6-1c82b802c344.filesusr.com
- c3f03ef5-5d46-427c-b53b-918515100afc.filesusr.com
- 1ae675fa-6ae0-4b2b-a8b9-44dd507bb590.filesusr.com
- 413d6933-354a-4c84-a91a-40189b9a0322.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report