MALICIOUS — c5d40f_e860e26dfccd4c11a2ca583ccd9c437e.pdf
MALICIOUS — c5d40f_e860e26dfccd4c11a2ca583ccd9c437e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
f95ab1b5e342e3da9a08ad5eb37989a92393e6ad4c5b54c205072ab68db8558b - SHA-1:
33c2743bf48db4cfe54a5cdd72579cefe2920903 - MD5:
5f63ec073a0f54d5cd5fa1ce91e6d36a - ssdeep:
768:9gGzpDKaWk34k5A3EJ3aJkwZN633ICT/Q1SgMVOw5Y4Y7Xu2iQqSrs7l5kgTvfWz:+GF2aZaJE3+LMVOweN7xi7SrQ3v+n - TLSH:
T17F34C0F32087ED4C76DAAF136DAA245AA585D78C5132E36044CD3A6CD07C2FC6F50A61 - Submitted as: c5d40f_e860e26dfccd4c11a2ca583ccd9c437e.pdf
- File type: pdf · Size: 57284 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.cc/wix?keyword=mutations+lesson+plan+middle+school, https://bf1ad6ef-f6a4-43dd-8ea9-82a4c3286e4e.filesusr.com/ugd/565485_26620e8415484ec895185b67a8a087e4.pdf?index=true, https://37cd0a03-e4c6-4b86-9322-43ff1f1f42bc.filesusr.com/ugd/610d21_3b4347a0118a4a07a8b9cfba13a6af45.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/wix?keyword=mutations+lesson+plan+middle+school
- https://bf1ad6ef-f6a4-43dd-8ea9-82a4c3286e4e.filesusr.com/ugd/565485_26620e8415484ec895185b67a8a087e4.pdf?index=true
- https://37cd0a03-e4c6-4b86-9322-43ff1f1f42bc.filesusr.com/ugd/610d21_3b4347a0118a4a07a8b9cfba13a6af45.pdf?index=true
- https://81175baa-3830-4166-bffe-9bd1b87f352a.filesusr.com/ugd/eb6612_664921a5dd144860a9b488292b3f9f94.pdf?index=true
- https://fb60ed15-61f0-4f66-8872-620ba323d532.filesusr.com/ugd/c57cae_5c6c4586b1e04e82be6540647288178b.pdf?index=true
- https://cdn.shopify.com/s/files/1/0431/5398/1589/files/vitamina_b7_biotina.pdf
- https://cdn.shopify.com/s/files/1/0431/3094/5693/files/pobapabumuzavasabimuv.pdf
- https://cdn.shopify.com/s/files/1/0428/1656/9500/files/relative_age_of_rocks_worksheet_answers.pdf
- http://rotela.seedsongfarm.org/uploads/1/3/1/6/131637308/aebbbdf2b3fc.pdf
- http://puvutajo.nsccfreedomtraining.com/uploads/1/3/2/6/132683071/dd714788a5ad00.pdf
- https://c992adc9-9ba3-4ebb-80ad-f1fde9f694d3.filesusr.com/ugd/610d21_95bfe831adba4547a869c5c6d645d0c0.pdf?index=true
- https://38a65549-86b7-4cc9-ad16-8f97b29f39d5.filesusr.com/ugd/277b62_b0b6d6f4bb3b42f0ae1bf285146a4e4a.pdf?index=true
- https://7a11ab84-cadd-4d32-bc38-de7d67d7b620.filesusr.com/ugd/7be1cd_539f6580d45c4c4d89b106a599172127.pdf?index=true
- https://3d8576e5-7465-4a04-8012-2dd00f5a615a.filesusr.com/ugd/682d1c_5622abd2fec84cda8a51c9e40f3aa918.pdf?index=true
- https://ac8ed247-a028-4f7d-8e4f-97707e600511.filesusr.com/ugd/7be1cd_249e2a36ae454631be279513b5c67ef1.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.cc
- bf1ad6ef-f6a4-43dd-8ea9-82a4c3286e4e.filesusr.com
- 37cd0a03-e4c6-4b86-9322-43ff1f1f42bc.filesusr.com
- 81175baa-3830-4166-bffe-9bd1b87f352a.filesusr.com
- fb60ed15-61f0-4f66-8872-620ba323d532.filesusr.com
- cdn.shopify.com
- rotela.seedsongfarm.org
- puvutajo.nsccfreedomtraining.com
- c992adc9-9ba3-4ebb-80ad-f1fde9f694d3.filesusr.com
- 38a65549-86b7-4cc9-ad16-8f97b29f39d5.filesusr.com
- 7a11ab84-cadd-4d32-bc38-de7d67d7b620.filesusr.com
- 3d8576e5-7465-4a04-8012-2dd00f5a615a.filesusr.com
- ac8ed247-a028-4f7d-8e4f-97707e600511.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report