MALICIOUS — bfbc46_47a707f04ee049dd889664eed8a97ddd.pdf
MALICIOUS — bfbc46_47a707f04ee049dd889664eed8a97ddd.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
328909ae630932267d36dc992f3d27be2e5c9a9aa9723138e2eb4afb24581a9c - SHA-1:
35b3a9922ceeafb25b3b01af09d7e25bd97328e4 - MD5:
0ec2112686dde41a516adda640d203cc - ssdeep:
3072:pFrAe0W9ybk38invVxUMNuJPXhizaXO0nDHnIC1kl+ep:Pf0W9ybk38Ev3UMsJ5izVmDa - TLSH:
T1113E01FB61CACC8CBA86D7236DA638586806C6943123EF541499762CC4F82BDEF51931 - Submitted as: bfbc46_47a707f04ee049dd889664eed8a97ddd.pdf
- File type: pdf · Size: 139393 bytes
- Verdict: malicious (88/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:Trojan.PDF.SBadur.gen (rule
UDS:Trojan.PDF.SBadur.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=do+fin+whales+have+special+adaptive+cruises, https://34dc6bb7-5ac5-4218-be9d-43db0681ab46.filesusr.com/ugd/2994dd_8b9ca765e3e1495a8115cbd4c44a1828.pdf?index=true, https://562a302e-0b38-4a59-a7c7-63f0623b643f.filesusr.com/ugd/ae15ca_ff1fb8054246481987d5ef953ae098e3.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/wix?keyword=do+fin+whales+have+special+adaptive+cruises
- https://34dc6bb7-5ac5-4218-be9d-43db0681ab46.filesusr.com/ugd/2994dd_8b9ca765e3e1495a8115cbd4c44a1828.pdf?index=true
- https://562a302e-0b38-4a59-a7c7-63f0623b643f.filesusr.com/ugd/ae15ca_ff1fb8054246481987d5ef953ae098e3.pdf?index=true
- https://2f076b5d-253e-4335-8b09-c05081c49740.filesusr.com/ugd/b85eb0_fa5124d0719b49e59b6ee8ac36cf3a70.pdf?index=true
- https://2aabcaf2-593b-41b3-b7cb-83d310f13e45.filesusr.com/ugd/8a4248_596920bfdccb44b3b589ce98a01ec961.pdf?index=true
- https://c397564b-31f9-49a0-b59e-e0c2bcf3a440.filesusr.com/ugd/a3b54b_e630d1452e0a41e8a02dbeaeacfdc401.pdf?index=true
- http://gifesemus.mohannadgharaibeh.com/uploads/1/3/0/7/130775565/f09d8615c3762.pdf
- http://files.athenspassportmagazine.com/uploads/1/3/0/8/130873717/1595525.pdf
- http://sitexada.pathwaystoinclusiveeducation.com/uploads/1/3/1/4/131437919/fugeluvenigova.pdf
- https://b4808514-6dd3-41cd-a125-039f28d0f7da.filesusr.com/ugd/685707_e29c7a016eb44fcbbdfa8d0e75042cbc.pdf?index=true
- https://72834f94-7e90-409d-a6d0-173937006289.filesusr.com/ugd/8db125_1562f1da8b59412c9bec13be1b1c2b4c.pdf?index=true
- https://18e94160-5a57-40ec-8de4-9d06861803dd.filesusr.com/ugd/2e79a6_bea8615b93f54e23ac79793a2759cc19.pdf?index=true
- https://4fbe0425-2124-487c-a12a-2f5e6c8f1741.filesusr.com/ugd/9f06f8_9952aa5b64b242d5a78dfae93a6ee390.pdf?index=true
- https://a8d4d9f4-4e4a-4458-b702-950a37c13c72.filesusr.com/ugd/e1c37d_91e0f30f7c744bf883d4def7e4942cd4.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- 34dc6bb7-5ac5-4218-be9d-43db0681ab46.filesusr.com
- 562a302e-0b38-4a59-a7c7-63f0623b643f.filesusr.com
- 2f076b5d-253e-4335-8b09-c05081c49740.filesusr.com
- 2aabcaf2-593b-41b3-b7cb-83d310f13e45.filesusr.com
- c397564b-31f9-49a0-b59e-e0c2bcf3a440.filesusr.com
- gifesemus.mohannadgharaibeh.com
- files.athenspassportmagazine.com
- sitexada.pathwaystoinclusiveeducation.com
- b4808514-6dd3-41cd-a125-039f28d0f7da.filesusr.com
- 72834f94-7e90-409d-a6d0-173937006289.filesusr.com
- 18e94160-5a57-40ec-8de4-9d06861803dd.filesusr.com
- 4fbe0425-2124-487c-a12a-2f5e6c8f1741.filesusr.com
- a8d4d9f4-4e4a-4458-b702-950a37c13c72.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report