MALICIOUS — d38238_9bdf05ccbfc74d0cbdc6c14436c66f57.pdf
MALICIOUS — d38238_9bdf05ccbfc74d0cbdc6c14436c66f57.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
ef2ef28f376d946544f068acf9b45e8c8e7346d0498c9e59aec00ebcdbf1065c - SHA-1:
ed12a8829637155bdbdaf341133a3a898f7e2470 - MD5:
fe61f319b90267fb9336ab7c9853a568 - ssdeep:
768:CgGzpDi1pZd1o42uWF2/xHlX4Mgk1WisJQNkhTkjcupHKf5:fGFOkILek1BtkJkDHe5 - TLSH:
T1FC308DF35197EC8C398B9B137EEB1549604AD6C86132A66044CC376CC47CAFEAE10924 - Submitted as: d38238_9bdf05ccbfc74d0cbdc6c14436c66f57.pdf
- File type: pdf · Size: 38069 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.club/wix?keyword=angles+in+quadrilaterals+worksheet+answer+key, http://tevad.petersonphysicaltherapyllc.com/uploads/1/3/1/6/131637148/pavawezebeta.pdf, http://tilonubep.tiltedhaggissoap.com/uploads/1/3/2/8/132814930/kibanikejupaw-zewixogefola-fosuja.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/wix?keyword=angles+in+quadrilaterals+worksheet+answer+key
- http://tevad.petersonphysicaltherapyllc.com/uploads/1/3/1/6/131637148/pavawezebeta.pdf
- http://tilonubep.tiltedhaggissoap.com/uploads/1/3/2/8/132814930/kibanikejupaw-zewixogefola-fosuja.pdf
- http://files.homewatcherlv.com/uploads/1/3/1/6/131606046/pepapefamoxu.pdf
- https://e2933c15-b17e-4a0e-b1d2-95ae9eb92249.filesusr.com/ugd/9f06f8_4c38ed3d0d42464fa7c87f0ea00ad41e.pdf?index=true
- https://ecf412be-4d74-4e21-a5c5-4e171a03540f.filesusr.com/ugd/8a9bcc_c1a94d3b411d4d4aa0bb3dec171a0244.pdf?index=true
- https://cdn.shopify.com/s/files/1/0439/5335/6955/files/longman_academic_reading_series.pdf
- https://cdn.shopify.com/s/files/1/0463/0278/9789/files/cancer_gastrico_causas.pdf
- https://cdn.shopify.com/s/files/1/0435/6741/5457/files/volokipawodamosumotefu.pdf
- https://cdn.shopify.com/s/files/1/0435/7763/9071/files/hernia_diafragmatica_pediatria.pdf
- https://89649f9a-db01-47d8-ad0c-ab6b2baf5d86.filesusr.com/ugd/a4d998_1f4f8c87004946b6a589dff777ebfaa7.pdf?index=true
- https://51b1cf4a-60ce-4d88-b028-68418f4a5249.filesusr.com/ugd/de3d83_8e1d737191a9484cadae39366b153031.pdf?index=true
- https://526419a3-b111-489a-8a73-ac3f3cfd7f64.filesusr.com/ugd/685707_327377cdf09a492db70ff367b20dc480.pdf?index=true
- https://25b0d0ae-071f-47cd-9bda-c09342683576.filesusr.com/ugd/89064d_6d336c291d2d4778b814a2e6e45387cb.pdf?index=true
- https://65105458-d040-4e00-b18e-a958128f087b.filesusr.com/ugd/370ea2_d86178f73c0844c3a0016c7c00b73d73.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.club
- tevad.petersonphysicaltherapyllc.com
- tilonubep.tiltedhaggissoap.com
- files.homewatcherlv.com
- e2933c15-b17e-4a0e-b1d2-95ae9eb92249.filesusr.com
- ecf412be-4d74-4e21-a5c5-4e171a03540f.filesusr.com
- cdn.shopify.com
- 89649f9a-db01-47d8-ad0c-ab6b2baf5d86.filesusr.com
- 51b1cf4a-60ce-4d88-b028-68418f4a5249.filesusr.com
- 526419a3-b111-489a-8a73-ac3f3cfd7f64.filesusr.com
- 25b0d0ae-071f-47cd-9bda-c09342683576.filesusr.com
- 65105458-d040-4e00-b18e-a958128f087b.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report