MALICIOUS — tagerezupubiji.pdf
MALICIOUS — tagerezupubiji.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (70/100), attributed to the SBadur family. 4 of 50 detection engines flagged it.
Identification
- SHA-256:
475105c3010bf4f4621616246ce7068078cddd2213f57af854a636623e1ffeb8 - SHA-1:
488d068d56b6fc27f963191c8f00c289ec015902 - MD5:
e8dcef6abe20c2adbc75e2b782c53689 - ssdeep:
3072:PFLpUuzoO5hbcEBpAXv+yNgCimoPsy1vpJtfRo6U:N97zoO55cEBpQm75SB - TLSH:
T13B3CE1B79173EC4D2D477B0399A90695719DD3C57122AF2452C4BB2CC0A87FCAF09AA0 - Submitted as: tagerezupubiji.pdf
- File type: pdf · Size: 112519 bytes
- Verdict: malicious (70/100) · Family: SBadur
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 70/100 is the fusion of 4 weighted signals:
- Kaspersky (KVRT) flagged UDS:Trojan.PDF.SBadur.gen (rule
UDS:Trojan.PDF.SBadur.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://cctraff.ru/wb?keyword=biblia%20interlineal%20griego%20espanol%20gratis, https://uploads.strikinglycdn.com/files/a43239c9-cb8e-4f3b-b030-00f926a6f041/5614432167.pdf, https://uploads.strikinglycdn.com/files/ebfb182b-9062-4638-839e-44023da7b951/xamuvapifugujesifezeruj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=biblia%20interlineal%20griego%20espanol%20gratis
- https://uploads.strikinglycdn.com/files/a43239c9-cb8e-4f3b-b030-00f926a6f041/5614432167.pdf
- https://uploads.strikinglycdn.com/files/ebfb182b-9062-4638-839e-44023da7b951/xamuvapifugujesifezeruj.pdf
- https://uploads.strikinglycdn.com/files/eb632243-5465-403b-85a2-577546cc75a7/jotiko.pdf
- https://uploads.strikinglycdn.com/files/ac36b77c-6897-4526-af56-d4cb71d16387/29586270900.pdf
- https://cdn.shopify.com/s/files/1/0495/5255/6184/files/android_phone_wont_connect_to_public_wifi.pdf
- https://cdn.shopify.com/s/files/1/0480/5289/5908/files/ootp_8_manual.pdf
- https://cdn.shopify.com/s/files/1/0431/8281/7441/files/goxasikutiz.pdf
- https://cdn.shopify.com/s/files/1/0440/1653/3654/files/yahweh_god_the_father.pdf
- https://cdn.shopify.com/s/files/1/0491/9151/8374/files/80_fl_oz_to_cups.pdf
- https://bijifejutumaxob.weebly.com/uploads/1/3/1/3/131381781/bidakibudatuj_papedo_miwexu_dojaj.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/rezareludufiven-voxodopi.pdf
- https://kidunaxu.weebly.com/uploads/1/3/1/4/131437100/witekugufig.pdf
- https://xutewosabog.weebly.com/uploads/1/3/2/3/132303209/loguvarurigesoruf.pdf
- https://gusumadanu.weebly.com/uploads/1/3/2/6/132695601/9b328ad073f8f.pdf
- https://tumovapexawezan.weebly.com/uploads/1/3/1/3/131398362/sejanudixono-jamog-vuloroludelowek.pdf
- https://cdn-cms.f-static.net/uploads/4368500/normal_5f881c1c86e8d.pdf
- https://cdn-cms.f-static.net/uploads/4370560/normal_5f88c2afcab43.pdf
- https://cdn-cms.f-static.net/uploads/4366964/normal_5f89bd64a00e8.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- bijifejutumaxob.weebly.com
- vuxozajuje.weebly.com
- kidunaxu.weebly.com
- xutewosabog.weebly.com
- gusumadanu.weebly.com
- tumovapexawezan.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
More SBadur samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report