MALICIOUS — 370ea2_d86178f73c0844c3a0016c7c00b73d73.pdf
MALICIOUS — 370ea2_d86178f73c0844c3a0016c7c00b73d73.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (78/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
e76ac17273158d147b80a28d17f0983786089f3b332ee1e1c637b9d4b8595861 - SHA-1:
02f8709eb3bb974dbebdc61401814b1e1e20c461 - MD5:
2533fa9b1c16aa441867a5ad66c2bce0 - ssdeep:
768:ogGzpDd/chhpN3I20aTaFH1DDS3imYzoAawdgKxu0uA+AwSD6y3:lGFB/PJaTMDuinMAZe5AxDJ3 - TLSH:
T17D32AEF3109BED887EC29B03AEEA11152186D74DB123EBB409997B3CC47C5BD6E50960 - Submitted as: 370ea2_d86178f73c0844c3a0016c7c00b73d73.pdf
- File type: pdf · Size: 43950 bytes
- Verdict: malicious (78/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 78/100 is the fusion of 5 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.com/wix?keyword=forces+worksheet+1st+grade, https://cdn.shopify.com/s/files/1/0429/8339/1395/files/zikokikuvuvexo.pdf, https://cdn.shopify.com/s/files/1/0432/6942/3269/files/zokifo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/wix?keyword=forces+worksheet+1st+grade
- https://cdn.shopify.com/s/files/1/0429/8339/1395/files/zikokikuvuvexo.pdf
- https://cdn.shopify.com/s/files/1/0432/6942/3269/files/zokifo.pdf
- https://cdn.shopify.com/s/files/1/0465/3380/4182/files/amoeba_sisters_multiple_alleles_work.pdf
- https://fe9376ad-ae9f-47f6-a1d4-e7eb3a72cb48.filesusr.com/ugd/4329d7_9e8048efc06042c1b2e4ab6c9903867c.pdf?index=true
- https://fcb6dd8a-3914-4aaf-b706-dee4fc1c8008.filesusr.com/ugd/c79b1c_576b9083c5c54bed92768394aaa268bb.pdf?index=true
- https://c511f236-9495-4ede-afda-a6325a4ad2c6.filesusr.com/ugd/8db125_bff8c80fbf8f4b39be59ded1caae2f94.pdf?index=true
- https://a34c4e6f-ebbd-46ad-89b4-eea9a34d52da.filesusr.com/ugd/26481d_407564f9ffbb43d8ad9e3fe25ea6ae41.pdf?index=true
- https://49929e0d-7a68-4aa8-a445-95f5953e9119.filesusr.com/ugd/d93890_0a9fbfc48a8f4c5bb7378e3484e6a365.pdf?index=true
- https://12191f27-282e-4eac-9df8-ca3f54363b39.filesusr.com/ugd/3be48b_b884f1503d5b4c1c9a93dc3808fb3234.pdf?index=true
- https://117abc11-069e-4e8f-8582-9a5e59bdc000.filesusr.com/ugd/36d413_10fa928bc2b142f687b8fd9db0da27b8.pdf?index=true
- https://58589832-2e99-4bea-865e-e3f7bb389d95.filesusr.com/ugd/314c35_e19e3e65dff242f08e70e64663099e78.pdf?index=true
- https://3f8249f8-32b1-4c9f-9b13-e604b46fe34e.filesusr.com/ugd/ade4e6_ba0086a49cdb4e50b178c84eab37f184.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- cdn.shopify.com
- fe9376ad-ae9f-47f6-a1d4-e7eb3a72cb48.filesusr.com
- fcb6dd8a-3914-4aaf-b706-dee4fc1c8008.filesusr.com
- c511f236-9495-4ede-afda-a6325a4ad2c6.filesusr.com
- a34c4e6f-ebbd-46ad-89b4-eea9a34d52da.filesusr.com
- 49929e0d-7a68-4aa8-a445-95f5953e9119.filesusr.com
- 12191f27-282e-4eac-9df8-ca3f54363b39.filesusr.com
- 117abc11-069e-4e8f-8582-9a5e59bdc000.filesusr.com
- 58589832-2e99-4bea-865e-e3f7bb389d95.filesusr.com
- 3f8249f8-32b1-4c9f-9b13-e604b46fe34e.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report