MALICIOUS — 7f614e_58d1b34bf4914d119953a3edcbc25151.pdf
MALICIOUS — 7f614e_58d1b34bf4914d119953a3edcbc25151.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
82fab885ebda85dae26e347cae4c1742c2b20ea48b36c68f66c146eecddf8917 - SHA-1:
bbc40c92f72349e324f84ebce0f88b6fd9e2d9ef - MD5:
7b43d5a1b5e6050e13120fdb72525d4e - ssdeep:
768:FgGzpDTNkX8vi9WBFLqcPB7iHPH58oK6+oV/7TefaUgGqgdhQOudHWSpp9ODlQOk:WGFv9BzZ7i/5XjeiiTXedHWwKlQOk - TLSH:
T1E834BFF311A7DC8C1AC2AF836EBE1599601697896572696885CD367DC07C3BC3F10A50 - Submitted as: 7f614e_58d1b34bf4914d119953a3edcbc25151.pdf
- File type: pdf · Size: 54530 bytes
- Verdict: malicious (88/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.link/wix?keyword=summoners+war+wind+epikion+priest+runes, http://files.magdazaslona.com/uploads/1/3/1/0/131071231/vemeviwovibuf-fodavo.pdf, http://files.thomasganzevoort.com/uploads/1/3/1/8/131856277/zetijeku-bapamukasefimij.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/wix?keyword=summoners+war+wind+epikion+priest+runes
- http://files.magdazaslona.com/uploads/1/3/1/0/131071231/vemeviwovibuf-fodavo.pdf
- http://files.thomasganzevoort.com/uploads/1/3/1/8/131856277/zetijeku-bapamukasefimij.pdf
- http://files.jlfitnutrition.com/uploads/1/3/1/3/131383604/e020c63df.pdf
- http://files.mariasfabrics.com/uploads/1/3/1/6/131606666/da2a0.pdf
- http://files.asiandmore.com/uploads/1/3/1/3/131382491/3185934.pdf
- http://files.eatonsquarebureau.com/uploads/1/3/0/8/130813357/5360411.pdf
- http://tilebez.robertoborgatta.org/uploads/1/3/0/7/130775350/gegis.pdf
- http://files.newdayforthetao.com/uploads/1/3/1/1/131164112/9bd337fdae49f.pdf
- http://zigep.npsarea12.com/uploads/1/3/1/4/131437308/6372e54cd3a9386.pdf
- http://files.erminsinanovic.com/uploads/1/3/2/3/132302998/nofumujoj.pdf
- http://files.onelinerjokelab.com/uploads/1/3/1/3/131381411/gosenewoxo_ketegakeses.pdf
- https://9a8acc00-0d6b-47ca-b683-894258a63dd1.filesusr.com/ugd/370021_9daa6d7640c8489b8dee50cef1448c92.pdf?index=true
- https://d63270ad-0122-408a-907a-fb41ca4bae62.filesusr.com/ugd/c5d40f_8d613205b5d8411080629113fe485273.pdf?index=true
- https://1f8da946-3c67-441a-b665-0e1592599125.filesusr.com/ugd/9cfd0a_7dbb82a9f4664563ad342b11bb058a59.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.link
- files.magdazaslona.com
- files.thomasganzevoort.com
- files.jlfitnutrition.com
- files.mariasfabrics.com
- files.asiandmore.com
- files.eatonsquarebureau.com
- tilebez.robertoborgatta.org
- files.newdayforthetao.com
- zigep.npsarea12.com
- files.erminsinanovic.com
- files.onelinerjokelab.com
- 9a8acc00-0d6b-47ca-b683-894258a63dd1.filesusr.com
- d63270ad-0122-408a-907a-fb41ca4bae62.filesusr.com
- 1f8da946-3c67-441a-b665-0e1592599125.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report