MALICIOUS — 61b8bf_01e621fb38d04afbb76430d9f32a3b4d.pdf
MALICIOUS — 61b8bf_01e621fb38d04afbb76430d9f32a3b4d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
7ad83e13bd5f8c38859456fecf959b1ba486dafbd03738cab9a0e7c7aaea3f09 - SHA-1:
04c9b2184104b347429687844951f47dab24ad16 - MD5:
ed5d18908436db1692b5c094240eec82 - ssdeep:
1536:8FGFeSA5Upoj9Chqb1NK+Wyhclm6g9mDIgV:8YFeSAOp0iqhczyhcM5mJ - TLSH:
T18E34CFF32597ED4C3E8B97035DE701A8A198DB8CA2738B6559883B3CD07C5ADBE50811 - Submitted as: 61b8bf_01e621fb38d04afbb76430d9f32a3b4d.pdf
- File type: pdf · Size: 56668 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.PDF.Agent.gen (rule
HEUR:Trojan.PDF.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.me/wix?keyword=shared+powers+of+congress, http://widobat.gammadiamonds.com/uploads/1/3/1/4/131407316/659446.pdf, http://sunaje.amaranthusestate.com/uploads/1/3/1/3/131379737/1089f126ed8ca9.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/wix?keyword=shared+powers+of+congress
- http://widobat.gammadiamonds.com/uploads/1/3/1/4/131407316/659446.pdf
- http://sunaje.amaranthusestate.com/uploads/1/3/1/3/131379737/1089f126ed8ca9.pdf
- http://files.cyniccritiq.com/uploads/1/3/1/4/131454523/zovuximezepo-sexudutufuku.pdf
- http://files.chrisavisartist.com/uploads/1/3/0/7/130776511/suzutopo_jobabujaw_lufosiwifolebuj_mixojik.pdf
- https://73437945-31ea-4a53-8f26-0b1049349dcd.filesusr.com/ugd/610d21_5ae5bab5df7546bb9dd6ffab81360259.pdf?index=true
- https://534d38a9-da7f-4fa7-9790-55fa6bc1911d.filesusr.com/ugd/f65518_f28324739e7c4e49b70435fff6c60772.pdf?index=true
- http://files.karikant.com/uploads/1/3/1/3/131379875/wufakoza.pdf
- http://mufiw.littlechristianpreschool.org/uploads/1/3/1/4/131453060/16f26fc48.pdf
- http://files.moongoat.com/uploads/1/3/1/3/131379828/xizujufodivu-teratesakujasij-xuxakomow.pdf
- http://files.rootsva.com/uploads/1/3/1/3/131398177/c81a18512.pdf
- http://files.hcmsystemslimited.co.uk/uploads/1/3/0/8/130814644/jebepu.pdf
- https://cdn.shopify.com/s/files/1/0438/3549/0461/files/alesis_3630_compressor_manual.pdf
- https://cdn.shopify.com/s/files/1/0433/6710/4668/files/ryobi_31cc_weedeater.pdf
- https://cdn.shopify.com/s/files/1/0430/6200/1821/files/11789266743.pdf
- https://cdn.shopify.com/s/files/1/0441/0903/7720/files/51715646103.pdf
- https://cdn.shopify.com/s/files/1/0433/7218/3703/files/6149651238.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.me
- widobat.gammadiamonds.com
- sunaje.amaranthusestate.com
- files.cyniccritiq.com
- files.chrisavisartist.com
- 73437945-31ea-4a53-8f26-0b1049349dcd.filesusr.com
- 534d38a9-da7f-4fa7-9790-55fa6bc1911d.filesusr.com
- files.karikant.com
- mufiw.littlechristianpreschool.org
- files.moongoat.com
- files.rootsva.com
- files.hcmsystemslimited.co.uk
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report