MALICIOUS — f2ef67_1c27a99dfc4e4fc7bff33f40fe45d568.pdf
MALICIOUS — f2ef67_1c27a99dfc4e4fc7bff33f40fe45d568.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e5985fc6c3160e4c0549f6d89070861c1d5cfb58bb60209fde9169fc20fa3249 - SHA-1:
6c0bc9eb496afb9d2b265e93943ba923fc88fbb0 - MD5:
c8133d597ca7f19cbcfd76c167ea44af - ssdeep:
1536:LGFYAaxP3aJ+ND+40ocZHAJI+KpxQqbm:qFYAaxP6WKocZHAJIvpxQ5 - TLSH:
T1E435C0F31097ED8D7A86AF1379EA215CA00AC64C513297A049DC7BACD47C6BDAF40721 - Submitted as: f2ef67_1c27a99dfc4e4fc7bff33f40fe45d568.pdf
- File type: pdf · Size: 60615 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:Trojan.PDF.SBadur.gen (rule
UDS:Trojan.PDF.SBadur.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.com/wix?keyword=randolph+county+warrant+check, https://cdn.shopify.com/s/files/1/0437/3997/1738/files/articulo_cientifico_cancer_de_prostata.pdf, https://cdn.shopify.com/s/files/1/0431/6083/0116/files/mubufa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/wix?keyword=randolph+county+warrant+check
- https://cdn.shopify.com/s/files/1/0437/3997/1738/files/articulo_cientifico_cancer_de_prostata.pdf
- https://cdn.shopify.com/s/files/1/0431/6083/0116/files/mubufa.pdf
- https://cdn.shopify.com/s/files/1/0463/3116/6881/files/wiwivoriwoxobinekevarezo.pdf
- https://cdn.shopify.com/s/files/1/0431/2468/7014/files/random_number_and_letter_generator.pdf
- https://ddd3045d-d77d-4598-815f-891a041f1dfc.filesusr.com/ugd/66f3f9_85d17334f750400b9453c963d6f25645.pdf?index=true
- https://6366ff8c-af4b-461e-96b0-431ad9f8d429.filesusr.com/ugd/a8ca0f_5bed3231d5b548ddb12ac37208ad63b5.pdf?index=true
- https://fc00db4a-e252-4578-9f4b-a855974103a5.filesusr.com/ugd/668a47_cbbe7a04bdf0486b8b4f57727beaed6d.pdf?index=true
- https://cdn.shopify.com/s/files/1/0430/6783/4517/files/90452782679.pdf
- https://cdn.shopify.com/s/files/1/0437/1673/9222/files/79879665380.pdf
- https://cdn.shopify.com/s/files/1/0433/8778/1287/files/charha_de_rang_song_djpunjab.pdf
- https://cdn.shopify.com/s/files/1/0434/6196/8025/files/97596070412.pdf
- https://cdn.shopify.com/s/files/1/0430/5177/8202/files/gegugevanaki.pdf
- https://7095df56-e002-482c-a894-c4670468f1b6.filesusr.com/ugd/665c20_8d7b57587fe04328bcecac2c6abacf1d.pdf?index=true
- https://91f9e142-1281-473f-b1a4-a101eccdda09.filesusr.com/ugd/510a18_ffde569e87e347788a371be3db79e139.pdf?index=true
- https://ec7d5e77-00c0-4a30-b8ea-88def8ab8879.filesusr.com/ugd/eb6612_990241b926ab448e89c3fa275371c006.pdf?index=true
- https://d1ca4fce-3646-4656-8cb6-447002612d24.filesusr.com/ugd/a32c20_de2c2c4ea6034a128e9af0a3799ef765.pdf?index=true
- https://4167fa27-5226-416f-b0a6-c9d0c2abbec1.filesusr.com/ugd/d5d855_9d785c7964c74854bedda3d2a4491d14.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- cdn.shopify.com
- ddd3045d-d77d-4598-815f-891a041f1dfc.filesusr.com
- 6366ff8c-af4b-461e-96b0-431ad9f8d429.filesusr.com
- fc00db4a-e252-4578-9f4b-a855974103a5.filesusr.com
- 7095df56-e002-482c-a894-c4670468f1b6.filesusr.com
- 91f9e142-1281-473f-b1a4-a101eccdda09.filesusr.com
- ec7d5e77-00c0-4a30-b8ea-88def8ab8879.filesusr.com
- d1ca4fce-3646-4656-8cb6-447002612d24.filesusr.com
- 4167fa27-5226-416f-b0a6-c9d0c2abbec1.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report