MALICIOUS — c638b7_948355b58dd7470c941f9235801f3b7a.pdf
MALICIOUS — c638b7_948355b58dd7470c941f9235801f3b7a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
de538c42079e591ea9786667f55dbdd0d73546c86bea1e0095f5c7926475a8d7 - SHA-1:
1d9e4a0285e2b8bab4d7a33eb2860b4462d13175 - MD5:
2b10c9bf27b94eb1a172d636a0b342fa - ssdeep:
768:ngGzpDM9YlIOuaUM5EHHgn9MSC+fM9XdzBf:gGFwu6OuaUMdnmS1MJdzBf - TLSH:
T1B6308DF314EBED8C759BAB03ADA60055A546C7886237976058C87B7CE4BC2BC6E10930 - Submitted as: c638b7_948355b58dd7470c941f9235801f3b7a.pdf
- File type: pdf · Size: 36144 bytes
- Verdict: malicious (88/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.cc/wix?keyword=smart+board+800+manual, http://lajuwifi.maggiejoynt.com/uploads/1/3/1/4/131453536/xexuvitipaw.pdf, http://files.jamesdykman.com/uploads/1/3/0/9/130969389/sawusugigatepo-tumosogeluxaz-solitunilisuxo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/wix?keyword=smart+board+800+manual
- http://lajuwifi.maggiejoynt.com/uploads/1/3/1/4/131453536/xexuvitipaw.pdf
- http://files.jamesdykman.com/uploads/1/3/0/9/130969389/sawusugigatepo-tumosogeluxaz-solitunilisuxo.pdf
- http://kuxixomil.arcpowerwashing.com/uploads/1/3/0/9/130969021/6927174.pdf
- http://files.omega-usa.org/uploads/1/3/1/4/131438439/wokevavewuto.pdf
- https://042c4413-4815-4431-9148-9ca25e3d9887.filesusr.com/ugd/3cb679_4264795adeb74e7d82947b4f653fdaed.pdf?index=true
- https://99d19926-65f0-42b0-bcbb-1ece389c399c.filesusr.com/ugd/24deb6_0afa0232420341958d29720c4f309fc3.pdf?index=true
- https://b9f710a6-dfac-4767-a5dd-42fc0e158b4a.filesusr.com/ugd/65b209_dd850d1cf2a64c7cb9c40c2dfa605ef0.pdf?index=true
- https://26a1bf29-e367-4a0f-92a8-772d946bd0da.filesusr.com/ugd/4329d7_c67d8ccbfa9246ffbc237411fb4db236.pdf?index=true
- https://1047b778-3d55-45ed-b98f-d89ab29f6046.filesusr.com/ugd/8e7730_5608b6970070400583a70a97cb86207e.pdf?index=true
- https://f669989f-5947-496e-8b1c-938ebf4a2fe1.filesusr.com/ugd/a58502_833a46d2d2b74a12bd08b919a3c84789.pdf?index=true
- https://b7273997-2a97-41fe-88d6-ffdb7d9a3d3c.filesusr.com/ugd/3bcfef_a94b1ddb07e94cfd98913d8e342bc90c.pdf?index=true
- https://b62f190d-c4d5-4acc-a4d3-a554b1142c38.filesusr.com/ugd/d5d855_b2dbba74657b421589f8ab5ac8b28586.pdf?index=true
- https://16d613fe-3da6-4b0c-881f-bdd2aff35ec2.filesusr.com/ugd/8acad3_c939feaf4b3a438f91501d2ebc6a73a2.pdf?index=true
- https://ee9b74b2-5e4d-4129-bbcf-8aadb0121d59.filesusr.com/ugd/162fe6_40e1306ff53541bb81400101f1154fbc.pdf?index=true
- https://5e7a7acd-3d34-4ae3-953a-748d65baa12a.filesusr.com/ugd/162fe6_475b400cf9a9414c8a46d55a40c2bdf7.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.cc
- lajuwifi.maggiejoynt.com
- files.jamesdykman.com
- kuxixomil.arcpowerwashing.com
- files.omega-usa.org
- 042c4413-4815-4431-9148-9ca25e3d9887.filesusr.com
- 99d19926-65f0-42b0-bcbb-1ece389c399c.filesusr.com
- b9f710a6-dfac-4767-a5dd-42fc0e158b4a.filesusr.com
- 26a1bf29-e367-4a0f-92a8-772d946bd0da.filesusr.com
- 1047b778-3d55-45ed-b98f-d89ab29f6046.filesusr.com
- f669989f-5947-496e-8b1c-938ebf4a2fe1.filesusr.com
- b7273997-2a97-41fe-88d6-ffdb7d9a3d3c.filesusr.com
- b62f190d-c4d5-4acc-a4d3-a554b1142c38.filesusr.com
- 16d613fe-3da6-4b0c-881f-bdd2aff35ec2.filesusr.com
- ee9b74b2-5e4d-4129-bbcf-8aadb0121d59.filesusr.com
- 5e7a7acd-3d34-4ae3-953a-748d65baa12a.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report