MALICIOUS — b916f4_020c3e218c104cc98eea50403990068b.pdf
MALICIOUS — b916f4_020c3e218c104cc98eea50403990068b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
ffb6d50c8ffd5c1b8011f5113fb20d827e0e8d28ebaef5944250602364ea44b0 - SHA-1:
2232aefacab082f738ed12903ac9749b8dc55f56 - MD5:
2fa96292f8391a632ea1ba7aeef71570 - ssdeep:
768:b0gGzpDJS+GiRrGdCGjUzGfFOyFnw81fAAAMFBaMW9azpQu4k3BhtC:9GFtSLWGtvnw8AkBaMWQzpQi3BhtC - TLSH:
T1B7329DF7559BEC8C7ACB9B03AEA205655489D38C6233E66448887B7CC93C1BD6E10D21 - Submitted as: b916f4_020c3e218c104cc98eea50403990068b.pdf
- File type: pdf · Size: 46681 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.PDF.Agent.gen (rule
HEUR:Trojan.PDF.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=steel+deck+institute+diaphragm+design+manual+third+edition+ddm03, https://54ce31c7-33fe-489d-b92f-f8be918dbbe2.filesusr.com/ugd/3a38e0_85809577ab3841a7bb335f247a82b0af.pdf?index=true, https://f4c1e8f2-6360-48c8-a968-9b6614304aec.filesusr.com/ugd/baa514_251d76da8ead4f0c96e22fb43ed88511.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/wix?keyword=steel+deck+institute+diaphragm+design+manual+third+edition+ddm03
- https://54ce31c7-33fe-489d-b92f-f8be918dbbe2.filesusr.com/ugd/3a38e0_85809577ab3841a7bb335f247a82b0af.pdf?index=true
- https://f4c1e8f2-6360-48c8-a968-9b6614304aec.filesusr.com/ugd/baa514_251d76da8ead4f0c96e22fb43ed88511.pdf?index=true
- https://4283a5f3-b5cf-4013-a278-33486ea7302a.filesusr.com/ugd/735189_7fe16acecbb04cb3a529dbc2c7d6a5c3.pdf?index=true
- https://0bb3ac2e-fc34-4800-9b08-a47dbcbb31a0.filesusr.com/ugd/dcc11b_eb8b4523fb1d4cf08660d9d72d9c904e.pdf?index=true
- http://files.priorityenvironmental.ca/uploads/1/3/2/7/132740415/poturowinu-pepurefeme-zomoxiru.pdf
- http://files.connielandis.com/uploads/1/3/0/7/130776607/beramajirutod_sefuborusi_zaxidiwagogone_kiwikawixige.pdf
- http://vuwomozu.artculturevs.org/uploads/1/3/1/3/131379394/debazemololumobug.pdf
- https://cdn.shopify.com/s/files/1/0430/6518/0314/files/short_form_berg_balance_scale.pdf
- https://cdn.shopify.com/s/files/1/0428/2561/3475/files/wikosidunusuvugom.pdf
- https://cdn.shopify.com/s/files/1/0430/9427/8293/files/19124130238.pdf
- https://cdn.shopify.com/s/files/1/0437/7755/6629/files/adecco_salary_guide_2019.pdf
- https://cdn.shopify.com/s/files/1/0431/4107/1016/files/24141463476.pdf
- https://f8b3e3f6-ee49-4644-b456-28f20539578b.filesusr.com/ugd/33ab24_6231f8dbe19a403d8c53e27f53444076.pdf?index=true
- https://3bd04b4b-1125-4e21-8644-03039bcb5463.filesusr.com/ugd/f6336d_46a7bbd825a948eeae30568084d59115.pdf?index=true
- https://7df6bab1-8c7f-46b5-b304-9bef67b70bb1.filesusr.com/ugd/c5d40f_6455e5df4b554cacb38cb50fe073c8a8.pdf?index=true
- https://76ce13fa-6817-4dd7-a765-0d69d0ea408c.filesusr.com/ugd/2dbf5a_ba7cc5c4474841caa555e54bd446ac36.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- 54ce31c7-33fe-489d-b92f-f8be918dbbe2.filesusr.com
- f4c1e8f2-6360-48c8-a968-9b6614304aec.filesusr.com
- 4283a5f3-b5cf-4013-a278-33486ea7302a.filesusr.com
- 0bb3ac2e-fc34-4800-9b08-a47dbcbb31a0.filesusr.com
- files.priorityenvironmental.ca
- files.connielandis.com
- vuwomozu.artculturevs.org
- cdn.shopify.com
- f8b3e3f6-ee49-4644-b456-28f20539578b.filesusr.com
- 3bd04b4b-1125-4e21-8644-03039bcb5463.filesusr.com
- 7df6bab1-8c7f-46b5-b304-9bef67b70bb1.filesusr.com
- 76ce13fa-6817-4dd7-a765-0d69d0ea408c.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report