MALICIOUS — 0d018b_598c46e5f21c42c8b941a85ad4eedf76.pdf
MALICIOUS — 0d018b_598c46e5f21c42c8b941a85ad4eedf76.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e2d465d5055c8b2620cd5f8d22830fc12cd76c822be168667de43a29ffd35e61 - SHA-1:
dea843a0415323e6d1b0169a164bef27dce34f86 - MD5:
841065aa3ca6150cfa48cc7d77fe8f98 - ssdeep:
768:BgGzpDB/OA7DJGVFCsVBS0DSlPsVhR+St0W6SwpypFxBm:yGFN5G/MPsVh4S16/KFxBm - TLSH:
T138318EF311ABEC8C36CBAB076AAA108D6549E78D7132E66449CC773CC57C6EC5E10621 - Submitted as: 0d018b_598c46e5f21c42c8b941a85ad4eedf76.pdf
- File type: pdf · Size: 42806 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.club/wix?keyword=designing+a+hand+warmer+lab+flinn+answers, http://files.yunkawasiperu.org/uploads/1/3/1/3/131379612/vizarifogumawov.pdf, http://files.whitethornherbals.com/uploads/1/3/1/1/131164531/9457913.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/wix?keyword=designing+a+hand+warmer+lab+flinn+answers
- http://files.yunkawasiperu.org/uploads/1/3/1/3/131379612/vizarifogumawov.pdf
- http://files.whitethornherbals.com/uploads/1/3/1/1/131164531/9457913.pdf
- http://pakud.berryheavenusa.com/uploads/1/3/1/8/131856439/gomunuk.pdf
- http://files.indianridgeland.com/uploads/1/3/1/8/131872055/e9a0fe8c81.pdf
- http://files.gmat.london/uploads/1/3/0/7/130740232/2923e7.pdf
- https://cdn.shopify.com/s/files/1/0481/4408/9241/files/hillsborough_township_public_schools_genesis.pdf
- https://031e39b9-e075-4b92-bc8c-b3573f193895.filesusr.com/ugd/c5d40f_5f6ebcae84b2460a9f132bec2a7e6151.pdf?index=true
- https://33f07765-ae8f-4e98-b02d-1c4aeb703797.filesusr.com/ugd/6e2da7_9999ea9799f74b26bd465cc65ca4fe91.pdf?index=true
- https://0f96b7d4-93f7-4b9b-adba-dfc93f9c2c31.filesusr.com/ugd/df7b34_f413609a406b42caa9a2ee9b3a4b1903.pdf?index=true
- https://cdn.shopify.com/s/files/1/0447/8212/5205/files/english_book_for_beginners.pdf
- https://cdn.shopify.com/s/files/1/0433/7323/2291/files/akuntansi_biaya_bahan_baku.pdf
- https://cdn.shopify.com/s/files/1/0429/9787/4851/files/pathophysiology_of_traumatic_brain_injury.pdf
- https://cdn.shopify.com/s/files/1/0434/5865/8456/files/pabetipivoxopisebazafaj.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.club
- files.yunkawasiperu.org
- files.whitethornherbals.com
- pakud.berryheavenusa.com
- files.indianridgeland.com
- cdn.shopify.com
- 031e39b9-e075-4b92-bc8c-b3573f193895.filesusr.com
- 33f07765-ae8f-4e98-b02d-1c4aeb703797.filesusr.com
- 0f96b7d4-93f7-4b9b-adba-dfc93f9c2c31.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
- files.gmat.london
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report