MALICIOUS — 10b03a_d90c7a01994b4f9b8a967630f7285493.pdf
MALICIOUS — 10b03a_d90c7a01994b4f9b8a967630f7285493.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (78/100). 2 of 54 detection engines flagged it.
Identification
- SHA-256:
c80a9836a9aa360ba74c494b439a34ebcdb0dced898a19aed6067dca5681b8d2 - SHA-1:
c2c58a8ca2ebb4ed3e7546fa51157a772267e116 - MD5:
5659b908a4cd95843701f5f1c2f2b2cd - ssdeep:
1536:mGFzZE8jSKMblempjvnTRxlHUytjOHeVPNWcSwlg541o70q9v:/FzZRjSHQmtvT3l07HCPzJlJe70E - TLSH:
T16D37B0F3108ADDC87EC6EF0379F62424A547DA983222DA5085DD7B7C847C27C9E21A61 - Submitted as: 10b03a_d90c7a01994b4f9b8a967630f7285493.pdf
- File type: pdf · Size: 75223 bytes
- Verdict: malicious (78/100)
Detections (2 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 78/100 is the fusion of 5 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.club/wix?keyword=v+number+in+alphabet, https://5d33a5fe-9623-459e-84a9-d982b2d3b952.filesusr.com/ugd/3225da_6979b89ff6ce470c86b9342039475b7b.pdf?index=true, https://3a1fbdfc-298e-45b0-bf3d-6fe5cfbb98cb.filesusr.com/ugd/5bb01c_19e8be63c39140f3ab3a01c7cc17e709.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/wix?keyword=v+number+in+alphabet
- https://5d33a5fe-9623-459e-84a9-d982b2d3b952.filesusr.com/ugd/3225da_6979b89ff6ce470c86b9342039475b7b.pdf?index=true
- https://3a1fbdfc-298e-45b0-bf3d-6fe5cfbb98cb.filesusr.com/ugd/5bb01c_19e8be63c39140f3ab3a01c7cc17e709.pdf?index=true
- https://430a6576-7ca3-4cb8-b372-59b9996aa759.filesusr.com/ugd/76aeb6_683fa6a33eae49119613a6b2331be973.pdf?index=true
- https://594743c3-78ae-4da5-881d-0c67c87967d1.filesusr.com/ugd/b7306e_db2239eae64742af80eca0445d270f6c.pdf?index=true
- https://d834be7b-a886-4d78-9f71-12d9b1dd83d9.filesusr.com/ugd/2994dd_c9ab5a3b85b648c680441dfe351e0157.pdf?index=true
- http://dowove.benefactoryllc.com/uploads/1/3/1/1/131164250/gisilizov.pdf
- https://494d5c9c-3482-438d-8bf1-f9182e84b8fb.filesusr.com/ugd/f1780b_5087df127cdb48dbbef7aa78271659ce.pdf?index=true
- https://40429b4b-d855-4b32-aa6b-cea0adbafd6d.filesusr.com/ugd/5bb01c_536037b408f84525b7b23cb12ad997e0.pdf?index=true
- https://33403046-6fe3-458a-a672-6cfe2b6b5298.filesusr.com/ugd/07e02c_37490d8ea8ec49b18008e88de9137a37.pdf?index=true
- https://cdn.shopify.com/s/files/1/0439/0099/3704/files/facilities_manager_job_description_template.pdf
- https://cdn.shopify.com/s/files/1/0430/3070/8385/files/56002925172.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.club
- 5d33a5fe-9623-459e-84a9-d982b2d3b952.filesusr.com
- 3a1fbdfc-298e-45b0-bf3d-6fe5cfbb98cb.filesusr.com
- 430a6576-7ca3-4cb8-b372-59b9996aa759.filesusr.com
- 594743c3-78ae-4da5-881d-0c67c87967d1.filesusr.com
- d834be7b-a886-4d78-9f71-12d9b1dd83d9.filesusr.com
- dowove.benefactoryllc.com
- 494d5c9c-3482-438d-8bf1-f9182e84b8fb.filesusr.com
- 40429b4b-d855-4b32-aa6b-cea0adbafd6d.filesusr.com
- 33403046-6fe3-458a-a672-6cfe2b6b5298.filesusr.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report