MALICIOUS — bfd504_d99f03fef0d74a018ff9c4b784b48459.pdf
MALICIOUS — bfd504_d99f03fef0d74a018ff9c4b784b48459.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b422084f97714de59aa46c5fb0266c1f4d6efa32b2820c7ce8519345e61a6f52 - SHA-1:
32d65a9bce3660d8750e8ccefc6f19404bf0f567 - MD5:
dfd2ed4d2824e3d209b44208d8d3c3b2 - ssdeep:
768:tgGzpD7tA1UPjnb1mG2IUl3WnNzrNRApOhRjieifOSAZiVqRmanxF3ffvyRqyoq:OGFPzb1mGRWc3ZmNAZOqRDjHvTyoq - TLSH:
T1F335CFF3249BEC487687A313BCA702561189C7CC713797645898BA3CD5BC6BD6F25820 - Submitted as: bfd504_d99f03fef0d74a018ff9c4b784b48459.pdf
- File type: pdf · Size: 59753 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.com/wix?keyword=onkyo+tx+nr809+review, http://ruzokarok.communionfellowship.org/uploads/1/3/1/4/131453850/vataredod-livutojagiv-lokunulepag-veseguse.pdf, http://files.athleticfootballgroup.com/uploads/1/3/1/8/131858791/3655000.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/wix?keyword=onkyo+tx+nr809+review
- http://ruzokarok.communionfellowship.org/uploads/1/3/1/4/131453850/vataredod-livutojagiv-lokunulepag-veseguse.pdf
- http://files.athleticfootballgroup.com/uploads/1/3/1/8/131858791/3655000.pdf
- http://defusizat.randallcb.com/uploads/1/3/1/4/131482975/kufubifituvusosovena.pdf
- http://files.takingcareyoga.com/uploads/1/3/1/3/131380397/5420824.pdf
- https://e778f431-7181-4272-94e1-4abb5b5e3831.filesusr.com/ugd/31bf02_8b1fe5697f994fdea0efef2ec65e0125.pdf?index=true
- https://0eedf28e-3290-49d5-95bd-b8106ebdb351.filesusr.com/ugd/61804c_5d85508cd48147cd90d1e500b46c8f9e.pdf?index=true
- https://64d33188-3f26-465f-9b3f-d94c4c839e79.filesusr.com/ugd/0ebc1f_40bf21dec15a45b9a3073b99d88cabc2.pdf?index=true
- https://b298ab1e-2155-45a8-a2cd-4b5356aeed67.filesusr.com/ugd/9c66ff_b1019189cfc243539a94e06fd12a8d12.pdf?index=true
- https://58a0bb44-8581-466b-a9a2-261713fa103a.filesusr.com/ugd/66f3f9_c3378f6462cb44f68dd81b921004e915.pdf?index=true
- https://cdn.shopify.com/s/files/1/0439/7016/6942/files/57572867962.pdf
- https://cdn.shopify.com/s/files/1/0435/5109/6993/files/libutoj.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/lunizededalusabunis.pdf
- https://cdn.shopify.com/s/files/1/0433/5216/2462/files/31993973548.pdf
- https://1b566c4b-a3bd-40fd-a4b2-ba8635f28cde.filesusr.com/ugd/3e9e83_5f513c5d4329436f8bc00d3cb5522f6c.pdf?index=true
- https://925d67e8-7da8-4297-938b-f14440db52a3.filesusr.com/ugd/89441e_d11e545ed3f14afda03ecdc3054ac91b.pdf?index=true
- https://8fcaeb92-6a75-49e1-9ca8-5d4ec67dc22a.filesusr.com/ugd/29c71c_3dfd7ad41a174af2b1973a349e589403.pdf?index=true
- https://a00ccbac-3637-4b09-a928-4c0e00d921a2.filesusr.com/ugd/29c71c_52756eb488694200a05bf95507602d6d.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- ruzokarok.communionfellowship.org
- files.athleticfootballgroup.com
- defusizat.randallcb.com
- files.takingcareyoga.com
- e778f431-7181-4272-94e1-4abb5b5e3831.filesusr.com
- 0eedf28e-3290-49d5-95bd-b8106ebdb351.filesusr.com
- 64d33188-3f26-465f-9b3f-d94c4c839e79.filesusr.com
- b298ab1e-2155-45a8-a2cd-4b5356aeed67.filesusr.com
- 58a0bb44-8581-466b-a9a2-261713fa103a.filesusr.com
- cdn.shopify.com
- 1b566c4b-a3bd-40fd-a4b2-ba8635f28cde.filesusr.com
- 925d67e8-7da8-4297-938b-f14440db52a3.filesusr.com
- 8fcaeb92-6a75-49e1-9ca8-5d4ec67dc22a.filesusr.com
- a00ccbac-3637-4b09-a928-4c0e00d921a2.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report