MALICIOUS — 269bb8_fa2f6c7bdaeb4ebd8f74b3977005f7ae.pdf
MALICIOUS — 269bb8_fa2f6c7bdaeb4ebd8f74b3977005f7ae.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
90df3290d9a780a42e90e4a4242d1c3b56e72de1b41e2311dc9f83f8142dca2a - SHA-1:
bc75ba213b4caccdb4d05c3d138f53bb570fe234 - MD5:
dd8556ad986f7f58f68822fc9813c8c8 - ssdeep:
1536:LGFyNIwafYWF9T8F3A4O/kNO3duhtNwilNfrBAuPGLIb:qFy6fHlsA4Ykg3dyblNfrCSGM - TLSH:
T1ED37E0F320A7DC8C3A5B1F97ADDB18A811969788702697645884737CC0787FE5E409B3 - Submitted as: 269bb8_fa2f6c7bdaeb4ebd8f74b3977005f7ae.pdf
- File type: pdf · Size: 76330 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:Trojan.PDF.SBadur.gen (rule
UDS:Trojan.PDF.SBadur.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.cc/wix?keyword=pharmacotherapy+casebook+answers+9th+edition+pdf, https://b9c03409-4293-4929-8509-3c006d319c5f.filesusr.com/ugd/ced2dc_639e2347d6a34c5cb14a5252967a550c.pdf?index=true, https://adeff610-8751-4cd4-ba90-c94e8c48daec.filesusr.com/ugd/cc3ca9_bc190c8a76af479ba3de140b21f707df.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/wix?keyword=pharmacotherapy+casebook+answers+9th+edition+pdf
- https://b9c03409-4293-4929-8509-3c006d319c5f.filesusr.com/ugd/ced2dc_639e2347d6a34c5cb14a5252967a550c.pdf?index=true
- https://adeff610-8751-4cd4-ba90-c94e8c48daec.filesusr.com/ugd/cc3ca9_bc190c8a76af479ba3de140b21f707df.pdf?index=true
- https://533fdec4-9a5e-4d3c-ae75-77ac8f404643.filesusr.com/ugd/b463f2_a5d6385c60ca4c09a4a4a981a5e9e18f.pdf?index=true
- https://f4dade7d-8aaf-4bcb-8057-22a601e1d7c6.filesusr.com/ugd/dcf311_8dfdeeef02d24ae89aee4ab7c2ea5dd0.pdf?index=true
- http://lexen.kerenwheeler.com/uploads/1/3/1/4/131406449/tugepuwekojol-gexaduf-xejaberu-zelofewolebuwi.pdf
- http://files.karolenakuhn.com/uploads/1/3/0/8/130814052/c09d65e6a6.pdf
- http://files.pointepoa.org/uploads/1/3/1/8/131858661/210639b19813bcb.pdf
- http://files.marquitalopez.com/uploads/1/3/1/4/131455158/9d5a695ff87cb9e.pdf
- http://files.studioandronico.com/uploads/1/3/1/4/131483372/niribe.pdf
- http://kanokef.pcbudgetsolutions.com/uploads/1/3/0/7/130775476/posipuviwosub.pdf
- http://files.fusionfightersdance.com/uploads/1/3/1/3/131381681/2ba09d9dcebfd1.pdf
- http://files.qecareereducation.ca/uploads/1/3/0/8/130874583/kakafofusipago.pdf
- https://cdn.shopify.com/s/files/1/0434/4843/4844/files/tikuxefovinivaxip.pdf
- https://cdn.shopify.com/s/files/1/0432/3957/1611/files/kofizakul.pdf
- https://cdn.shopify.com/s/files/1/0435/8841/9741/files/85375588886.pdf
- https://cdn.shopify.com/s/files/1/0431/5670/1346/files/sixofasezob.pdf
- https://cdn.shopify.com/s/files/1/0437/9167/9637/files/85925226487.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.cc
- b9c03409-4293-4929-8509-3c006d319c5f.filesusr.com
- adeff610-8751-4cd4-ba90-c94e8c48daec.filesusr.com
- 533fdec4-9a5e-4d3c-ae75-77ac8f404643.filesusr.com
- f4dade7d-8aaf-4bcb-8057-22a601e1d7c6.filesusr.com
- lexen.kerenwheeler.com
- files.karolenakuhn.com
- files.pointepoa.org
- files.marquitalopez.com
- files.studioandronico.com
- kanokef.pcbudgetsolutions.com
- files.fusionfightersdance.com
- files.qecareereducation.ca
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report