MALICIOUS — f26382ce38bd1.pdf
MALICIOUS — f26382ce38bd1.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the SBadur family. 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1f3090e621019a081ac50ed2670a32fee502c1d61e2282effcf2a3a95c25db59 - SHA-1:
42cbc5a20f14bad827c6591bf9d4005305b7e6c6 - MD5:
c548af59c268a1c3868db44d43f9fa09 - ssdeep:
1536:1GFueJKq4PgMap0jJ1NxoUPe/0jONnFLeMp1/hW:IFueJFbOJ1N6UWcjONnFaMp1c - TLSH:
T1B837DFF320A7ED8D7646AF03A9AA209A2586C74DB03AA394448C7B1DD57C2BC3D51D70 - Submitted as: f26382ce38bd1.pdf
- File type: pdf · Size: 73816 bytes
- Verdict: malicious (93/100) · Family: SBadur
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 93/100 is the fusion of 6 weighted signals:
- Embedded link rated malicious by URL analysis: https://vodipewelo.weebly.com/uploads/1/3/1/6/131637384/8808719.pdf - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:Trojan.PDF.SBadur.gen (rule
UDS:Trojan.PDF.SBadur.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://cctraff.ru/wb?keyword=tv%20guide%20cocoa%20beach, https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/tupexokunodokoz-fogemevanonikiw-gugiwabutilu-lopefetunom.pdf, https://vodipewelo.weebly.com/uploads/1/3/1/6/131637384/8808719.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=tv%20guide%20cocoa%20beach
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/tupexokunodokoz-fogemevanonikiw-gugiwabutilu-lopefetunom.pdf
- https://vodipewelo.weebly.com/uploads/1/3/1/6/131637384/8808719.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/weveli.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/3257372.pdf
- https://vebifejelib.weebly.com/uploads/1/3/0/7/130775119/2526648.pdf
- https://pimupaxepa.weebly.com/uploads/1/3/1/8/131857198/6e0d65838d805.pdf
- https://cdn.shopify.com/s/files/1/0502/1673/0799/files/tedom.pdf
- https://cdn.shopify.com/s/files/1/0478/3567/6831/files/13279253986.pdf
- https://cdn.shopify.com/s/files/1/0481/7731/5989/files/xobuxonaralutuwavilo.pdf
- https://cdn.shopify.com/s/files/1/0266/9087/9667/files/mojotusosefegijiludid.pdf
- https://cdn.shopify.com/s/files/1/0266/8353/9644/files/zamum.pdf
- https://uploads.strikinglycdn.com/files/c2db50c9-e016-4399-9cb9-8295a719f2d9/82625321984.pdf
- https://uploads.strikinglycdn.com/files/79e35e94-00c7-45fd-b06d-b3b5cae924da/naxali.pdf
- https://uploads.strikinglycdn.com/files/9b8eda56-0f4e-460f-9298-945270ed9617/95375876139.pdf
- https://uploads.strikinglycdn.com/files/d28eae70-e8e2-4b15-8c77-12993a0a279b/ziporufisunudapisifodat.pdf
- https://cdn.shopify.com/s/files/1/0500/2674/1947/files/willamette_national_forest_hikes.pdf
- https://cdn.shopify.com/s/files/1/0492/6429/6092/files/tevabapinexirig.pdf
- https://cdn.shopify.com/s/files/1/0502/2148/2142/files/where_is_the_ravenclaw_common_room_in_minecraft.pdf
- https://cdn.shopify.com/s/files/1/0439/5030/9531/files/carolina_auto_spa_apex_north_carolina.pdf
- https://cdn.shopify.com/s/files/1/0266/8757/0105/files/air_mass_worksheet_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0461/0877/0467/files/zombie_prom_script.pdf
- https://cdn.shopify.com/s/files/1/0488/4080/2469/files/form_no_13_income_tax.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- vilukenuxe.weebly.com
- vodipewelo.weebly.com
- babikovinemixe.weebly.com
- vuxozajuje.weebly.com
- vebifejelib.weebly.com
- pimupaxepa.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
More SBadur samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report