MALICIOUS — 44b221_a1c4681859be49c3bee95f81a5ee4bf0.pdf
MALICIOUS — 44b221_a1c4681859be49c3bee95f81a5ee4bf0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
d23bc81aa06cab525edd4cf25ab8e7225360e02323751c52e13b08e9b54237ee - SHA-1:
f6ccef484653b32abf741f6d3146bfc68b64f311 - MD5:
ea0d6846862a47d9a60474c0ea4cefd4 - ssdeep:
1536:iGFvfw4Fc8euxyVCqqDEAXAnWbRXO8Uh5L6XtSrYWsfeQUS2Zu/H3w:bFvf/cZWyVCqqwAXrRFyQeQUS2Zuo - TLSH:
T11139F1F7101FEC8DB4CF9B43AD3A1456A085C7497271AA6009D97B9CE6BC1BDAD80930 - Submitted as: 44b221_a1c4681859be49c3bee95f81a5ee4bf0.pdf
- File type: pdf · Size: 90041 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:Trojan.PDF.SBadur.gen (rule
UDS:Trojan.PDF.SBadur.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.com/wix?keyword=how+to+use+nexus+mod+manager+oblivion, http://files.entrepreneur-srilanka.com/uploads/1/3/0/8/130874284/zizabujivu.pdf, http://files.silveroakshoa.com/uploads/1/3/1/6/131636872/4e0d9553.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/wix?keyword=how+to+use+nexus+mod+manager+oblivion
- http://files.entrepreneur-srilanka.com/uploads/1/3/0/8/130874284/zizabujivu.pdf
- http://files.silveroakshoa.com/uploads/1/3/1/6/131636872/4e0d9553.pdf
- http://files.mistrasgrouplearncenter.com/uploads/1/3/1/1/131163533/nugetivo.pdf
- http://files.martijoyoga.com/uploads/1/3/2/6/132681690/02034fb668f08cd.pdf
- https://cdn.shopify.com/s/files/1/0432/4101/3415/files/nojadudobamawo.pdf
- https://cdn.shopify.com/s/files/1/0428/2492/5351/files/fleck_5600_manual.pdf
- https://cdn.shopify.com/s/files/1/0433/9043/5495/files/herbert_blumer_symbolic_interactionism.pdf
- https://cdn.shopify.com/s/files/1/0432/1991/0813/files/17241175395.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/5866669006.pdf
- http://files.mayadabellydance.com/uploads/1/3/2/7/132710753/32dea2850.pdf
- http://files.arcguam.com/uploads/1/3/1/1/131163563/beditoxuxob_lawade_kupujotoribi_gavet.pdf
- http://witafi.evaairways.org/uploads/1/3/0/7/130740235/6d2c4ff249.pdf
- https://cdn.shopify.com/s/files/1/0438/1320/8224/files/leica_rangemaster_crf_1600-b_manual.pdf
- https://cdn.shopify.com/s/files/1/0431/6895/6565/files/cheetah_bengali_movie_hd.pdf
- https://cdn.shopify.com/s/files/1/0437/8342/2109/files/gezaxedimem.pdf
- https://cdn.shopify.com/s/files/1/0433/5281/7832/files/sibosivobegefenutavuvumuw.pdf
- https://cdn.shopify.com/s/files/1/0430/0334/7098/files/get_gmod_for_free.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- files.entrepreneur-srilanka.com
- files.silveroakshoa.com
- files.mistrasgrouplearncenter.com
- files.martijoyoga.com
- cdn.shopify.com
- files.mayadabellydance.com
- files.arcguam.com
- witafi.evaairways.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report