MALICIOUS — fb5067_b13f761e29a1474684bc2adcaf3c822e.pdf
MALICIOUS — fb5067_b13f761e29a1474684bc2adcaf3c822e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
72489d2f9528a9af79fc9c1f009e026b76a5d21c920510dccb66f07de0854267 - SHA-1:
fa9bac917274781850ad53b90045ccc27b89319e - MD5:
183f75e8f285652aa357db081bedd9da - ssdeep:
768:HgGzpDnAW7Dey04YcLI94ZUKkZAqEvYuw1IEUcT78Hbi1ZycvNy7A4Dc5G/:AGFLzvI94ZMNEQTw7SEcvcA4Dc5G/ - TLSH:
T18832AFF3507BED8C7B8FAB035AE62145658AD74D60239E9015C8772DC8BC6ED6F00A21 - Submitted as: fb5067_b13f761e29a1474684bc2adcaf3c822e.pdf
- File type: pdf · Size: 46783 bytes
- Verdict: malicious (88/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:Trojan.PDF.SBadur.gen (rule
UDS:Trojan.PDF.SBadur.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.com/wix?keyword=what+it+means+to+be+alive+today, https://ef3a7c03-e00b-4ace-82e0-26148360d28e.filesusr.com/ugd/6f9b04_4f52a69043b3480cb59d90c362d608ed.pdf?index=true, https://932c3435-885b-4361-8247-63414807ac8e.filesusr.com/ugd/58a813_5ba0178f60964495acddffbbf03c9245.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/wix?keyword=what+it+means+to+be+alive+today
- https://ef3a7c03-e00b-4ace-82e0-26148360d28e.filesusr.com/ugd/6f9b04_4f52a69043b3480cb59d90c362d608ed.pdf?index=true
- https://932c3435-885b-4361-8247-63414807ac8e.filesusr.com/ugd/58a813_5ba0178f60964495acddffbbf03c9245.pdf?index=true
- https://27144924-e31e-4a09-b06b-5c81785547b8.filesusr.com/ugd/5f226b_55544cf017774a32ba92aac2710c6ec6.pdf?index=true
- https://501b25a3-4b26-4e0f-8c03-6364387d18f3.filesusr.com/ugd/8bf3fc_cd66aef69b4c476a81371651f073792a.pdf?index=true
- https://26ac6772-3093-431b-82ad-cad14d4e3625.filesusr.com/ugd/ac8c68_ef5c1edf35f94bdb8731d379ebe630fc.pdf?index=true
- https://40429b4b-d855-4b32-aa6b-cea0adbafd6d.filesusr.com/ugd/5bb01c_536037b408f84525b7b23cb12ad997e0.pdf?index=true
- https://44deaf67-246a-489c-be83-d57b703e94d5.filesusr.com/ugd/3be48b_c1b9b9500464497585ab58cb5e8eec9c.pdf?index=true
- https://4af0a01b-7cbc-4e2e-856e-cbe8ecd02381.filesusr.com/ugd/18f527_3d02f6ef78ae46ad9000f6d857408126.pdf?index=true
- https://cdn.shopify.com/s/files/1/0432/1797/7504/files/34868623092.pdf
- https://cdn.shopify.com/s/files/1/0430/9726/0192/files/aircraft_weight_and_balance_form.pdf
- https://cdn.shopify.com/s/files/1/0437/6847/9893/files/26468995413.pdf
- https://cdn.shopify.com/s/files/1/0438/1147/1520/files/76198321715.pdf
- https://cdn.shopify.com/s/files/1/0428/0995/0367/files/48361070511.pdf
- https://cdn.shopify.com/s/files/1/0429/3351/8489/files/basic_english_grammar_book_1_with_answers.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- ef3a7c03-e00b-4ace-82e0-26148360d28e.filesusr.com
- 932c3435-885b-4361-8247-63414807ac8e.filesusr.com
- 27144924-e31e-4a09-b06b-5c81785547b8.filesusr.com
- 501b25a3-4b26-4e0f-8c03-6364387d18f3.filesusr.com
- 26ac6772-3093-431b-82ad-cad14d4e3625.filesusr.com
- 40429b4b-d855-4b32-aa6b-cea0adbafd6d.filesusr.com
- 44deaf67-246a-489c-be83-d57b703e94d5.filesusr.com
- 4af0a01b-7cbc-4e2e-856e-cbe8ecd02381.filesusr.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report