MALICIOUS — 8db125_6b6ad0eaa58347008516574d53c7922c.pdf
MALICIOUS — 8db125_6b6ad0eaa58347008516574d53c7922c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
9a2d4d8e257c4cbde0f4be0b2d514290f7a3d7cea187df246faeeba3c2977da9 - SHA-1:
261ffa09f97dc08af4bbe57d90165d701884dac0 - MD5:
dfb1c0d85e916eaa40e7b4d7c2895691 - ssdeep:
1536:KGFzO7cpGoqVRNjyIZAM3PQTfYrXy9EUH:zFz0cpGoOLjHixwm9X - TLSH:
T1E9339EF350ABEE0CB547AB036DEB115D9481E7C96122ABA05588AB3CC57C33D6F50A60 - Submitted as: 8db125_6b6ad0eaa58347008516574d53c7922c.pdf
- File type: pdf · Size: 49918 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.me/wix?keyword=how+to+start+writing+a+narrative+essay, https://e3786523-069a-4075-b623-25038ffda1c4.filesusr.com/ugd/e948c1_8b371dbc290e4c5d95bb104b417b6288.pdf?index=true, https://7eec2876-22ef-4d7a-9bbe-9c9cabbcfde6.filesusr.com/ugd/bb05c1_3393cd3b6d0b4546ba17a0493dd99860.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/wix?keyword=how+to+start+writing+a+narrative+essay
- https://e3786523-069a-4075-b623-25038ffda1c4.filesusr.com/ugd/e948c1_8b371dbc290e4c5d95bb104b417b6288.pdf?index=true
- https://7eec2876-22ef-4d7a-9bbe-9c9cabbcfde6.filesusr.com/ugd/bb05c1_3393cd3b6d0b4546ba17a0493dd99860.pdf?index=true
- https://709e5b45-1594-4ed3-b68b-b1886209f51d.filesusr.com/ugd/3be48b_708e058c02f54cf5922a5d1de5998ce8.pdf?index=true
- https://40429b4b-d855-4b32-aa6b-cea0adbafd6d.filesusr.com/ugd/5bb01c_536037b408f84525b7b23cb12ad997e0.pdf?index=true
- https://dcf39d67-7511-4a34-81b2-fd36b781c2da.filesusr.com/ugd/1cc777_cfc039c139654439a45887b3c7b36393.pdf?index=true
- http://files.aprenderyaonline.com/uploads/1/3/2/7/132710797/pudolu_wubufajagadoxa.pdf
- http://javules.midamericaallianceforafricanstudies.org/uploads/1/3/1/4/131437657/jisuguk.pdf
- http://files.healthysettings.org/uploads/1/3/2/6/132681409/583a374b9c21.pdf
- http://zuzokezop.400rusticstation.com/uploads/1/3/2/7/132710575/dodeve-jeridozekipom.pdf
- http://zokosixe.tuxpeoplesmusic.com/uploads/1/3/0/7/130775432/9f6abed7f.pdf
- http://gurewa.pursewithpurpose.org/uploads/1/3/1/0/131070786/4263438.pdf
- http://files.voanandivy.com/uploads/1/3/1/3/131398131/761dffac29.pdf
- https://3f0ed35c-b752-4556-bd54-2f8b1d0bf816.filesusr.com/ugd/c83fdb_cf7ade6deea94f70a1908aec1e6aada4.pdf?index=true
- https://6b8ff32a-f6b8-44f7-bd98-be156d557a69.filesusr.com/ugd/02af14_1444ad9db2e5496180e0c229051cb2ae.pdf?index=true
- https://6e0a538a-c332-4a01-9a31-3f0431ba1fea.filesusr.com/ugd/011e4b_75ac6ffabf964129bcc97ec27cb1735c.pdf?index=true
- https://794ffeaa-2844-43f5-a295-5fb02bb157ab.filesusr.com/ugd/6f7357_2a7e997e20b240279e64c9d497908019.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.me
- e3786523-069a-4075-b623-25038ffda1c4.filesusr.com
- 7eec2876-22ef-4d7a-9bbe-9c9cabbcfde6.filesusr.com
- 709e5b45-1594-4ed3-b68b-b1886209f51d.filesusr.com
- 40429b4b-d855-4b32-aa6b-cea0adbafd6d.filesusr.com
- dcf39d67-7511-4a34-81b2-fd36b781c2da.filesusr.com
- files.aprenderyaonline.com
- javules.midamericaallianceforafricanstudies.org
- files.healthysettings.org
- zuzokezop.400rusticstation.com
- zokosixe.tuxpeoplesmusic.com
- gurewa.pursewithpurpose.org
- files.voanandivy.com
- 3f0ed35c-b752-4556-bd54-2f8b1d0bf816.filesusr.com
- 6b8ff32a-f6b8-44f7-bd98-be156d557a69.filesusr.com
- 6e0a538a-c332-4a01-9a31-3f0431ba1fea.filesusr.com
- 794ffeaa-2844-43f5-a295-5fb02bb157ab.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report