MALICIOUS — c33f71_54fac909f2bf45598b6b99a10ed15c14.pdf
MALICIOUS — c33f71_54fac909f2bf45598b6b99a10ed15c14.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e9854073f0b76e5e0aa6b7ca0fcda16bf630a5571dd5ef03ca18fa5b15f14f5e - SHA-1:
ce3688b8068674ff824a6e94b80349a2af1733e9 - MD5:
1ce3a4650acb2fcb99ee57d218c4cb48 - ssdeep:
768:ugGzpD3dWXRL3eQKsxX4+P2rmINZx+o5LwGh5JhFfQTvQSS+R:LGFLYLeQDX4c2yWp5Lw85vFf25Sq - TLSH:
T1382F8DF35497EC4C66CF6F079EAA10596186D3896127A77018D87B3CD4786FCAE00970 - Submitted as: c33f71_54fac909f2bf45598b6b99a10ed15c14.pdf
- File type: pdf · Size: 35445 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:Trojan.PDF.SBadur.gen (rule
UDS:Trojan.PDF.SBadur.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.cc/wix?keyword=manual+locus+map, https://4d972195-9a66-402d-9d37-cb38e5de8957.filesusr.com/ugd/b361c6_950ebde851d94e9caa61737874458ddd.pdf?index=true, https://cacc9e2e-de09-4dc9-b781-eeaa18c9b3c2.filesusr.com/ugd/a4e402_eb743b93be1445e3bf026a5695cc6934.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/wix?keyword=manual+locus+map
- https://4d972195-9a66-402d-9d37-cb38e5de8957.filesusr.com/ugd/b361c6_950ebde851d94e9caa61737874458ddd.pdf?index=true
- https://cacc9e2e-de09-4dc9-b781-eeaa18c9b3c2.filesusr.com/ugd/a4e402_eb743b93be1445e3bf026a5695cc6934.pdf?index=true
- https://d039a675-4bb6-4230-8e39-84d44371539d.filesusr.com/ugd/035627_e986c37da41b4c6da0759526f85c5016.pdf?index=true
- https://00af6d0a-f362-4767-bc4a-c74048b4a2a9.filesusr.com/ugd/e49726_91459c727e264e2983c1037614126cae.pdf?index=true
- https://b9c55fe4-06d9-4e5d-8797-f6f850ac25c5.filesusr.com/ugd/2eedf1_b8f10f97fbb14571b8ac02b4065ce05a.pdf?index=true
- https://1463c31b-20f7-49ab-a9f3-ed074a0c4b8f.filesusr.com/ugd/5b9a87_1391a00ebaa74e44ac54be59ab3e320d.pdf?index=true
- https://e15e4ed3-6649-4708-a818-06dfd1edf041.filesusr.com/ugd/d7c203_fe17213e12904c018e4ac3d8ae640b22.pdf?index=true
- https://88d175b0-61ac-4578-87fa-e27f5efd1192.filesusr.com/ugd/bb3bf9_908425142f84468a836d805af5aa3d6a.pdf?index=true
- https://1e1d88bf-35fe-4b70-ace7-d31bf88b5127.filesusr.com/ugd/64e449_6eebd695ae744663a13564d9fd35e0c9.pdf?index=true
- https://b3b708db-b2a3-4cd2-88c8-6012c62e2479.filesusr.com/ugd/ad2ade_9d4d12ef8ec44d1d960fc88c9b48016a.pdf?index=true
- https://69244a2d-9942-4e63-a911-5f4f6422d967.filesusr.com/ugd/70e5f7_92dd2ecdd87144b4b00472f0ebe8b649.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.cc
- 4d972195-9a66-402d-9d37-cb38e5de8957.filesusr.com
- cacc9e2e-de09-4dc9-b781-eeaa18c9b3c2.filesusr.com
- d039a675-4bb6-4230-8e39-84d44371539d.filesusr.com
- 00af6d0a-f362-4767-bc4a-c74048b4a2a9.filesusr.com
- b9c55fe4-06d9-4e5d-8797-f6f850ac25c5.filesusr.com
- 1463c31b-20f7-49ab-a9f3-ed074a0c4b8f.filesusr.com
- e15e4ed3-6649-4708-a818-06dfd1edf041.filesusr.com
- 88d175b0-61ac-4578-87fa-e27f5efd1192.filesusr.com
- 1e1d88bf-35fe-4b70-ace7-d31bf88b5127.filesusr.com
- b3b708db-b2a3-4cd2-88c8-6012c62e2479.filesusr.com
- 69244a2d-9942-4e63-a911-5f4f6422d967.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report