MALICIOUS — 63123db.pdf
MALICIOUS — 63123db.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the SBadur family. 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5c8033f1843e660cb90f1f6baba119d4b9911a0a23c4d496d5c3cc427d080b47 - SHA-1:
ee2ed70e3adf7473f3ece16824262fcf3921dbc7 - MD5:
44e4b1b445af711dec5a889bc27a0da6 - ssdeep:
768:ygGzpDGpWm23jAyriDa4/TxWzTmhhx9dw1XjikAvCJ5/jFFvC:vGFKpWfiO4/TxWHmLGzikio5/jFFvC - TLSH:
T1FC329DF35093EC4CBA4BDB43AEA710A9558AD34CA13BD760448CB72CC0BC5BD6E51920 - Submitted as: 63123db.pdf
- File type: pdf · Size: 46250 bytes
- Verdict: malicious (87/100) · Family: SBadur
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 87/100 is the fusion of 5 weighted signals:
- Embedded link rated malicious by URL analysis: https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/8279107.pdf - network signal, weight 0.70, confidence 0.80
- Kaspersky (KVRT) flagged UDS:Trojan.PDF.SBadur.gen (rule
UDS:Trojan.PDF.SBadur.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://cctraff.ru/wb?keyword=dyson%20hot%20cool%20reviews, https://uploads.strikinglycdn.com/files/70cb7571-a71f-4db1-883b-8a3a3b6a2804/bamudafanenobotet.pdf, https://uploads.strikinglycdn.com/files/e80bbd3e-add7-4bd8-b731-f5f680c6b4ef/64347302930.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=dyson%20hot%20cool%20reviews
- https://uploads.strikinglycdn.com/files/70cb7571-a71f-4db1-883b-8a3a3b6a2804/bamudafanenobotet.pdf
- https://uploads.strikinglycdn.com/files/e80bbd3e-add7-4bd8-b731-f5f680c6b4ef/64347302930.pdf
- https://uploads.strikinglycdn.com/files/676f2403-8e3f-484e-8dc5-c3234ee4074c/20706312919.pdf
- https://uploads.strikinglycdn.com/files/dc97d18b-7b5c-4c28-812f-0f426f09627e/27964419989.pdf
- https://uploads.strikinglycdn.com/files/a1114780-2fb3-4a0d-8eb6-8694ceb08b89/10068119025.pdf
- https://wopuremob.weebly.com/uploads/1/3/2/6/132696580/9068577.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/8279107.pdf
- https://dejolezeg.weebly.com/uploads/1/3/2/8/132815968/duvipezukowa.pdf
- https://rimesozarabef.weebly.com/uploads/1/3/1/6/131607712/lupakemufeden-rujivod-xuponelotisake-bavamedabibiro.pdf
- https://cdn-cms.f-static.net/uploads/4379473/normal_5f8a9e00880d7.pdf
- https://cdn-cms.f-static.net/uploads/4367286/normal_5f8d52c88efb3.pdf
- https://cdn-cms.f-static.net/uploads/4367621/normal_5f898764ec4ee.pdf
- https://cdn-cms.f-static.net/uploads/4368952/normal_5f87aaaf35cee.pdf
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/5061767.pdf
- https://kokubexajaluk.weebly.com/uploads/1/3/2/6/132681668/jomedalapab-ganuginezez-zixejelu-xadupukasupelal.pdf
- https://goduvozimaku.weebly.com/uploads/1/3/1/3/131380582/7539717.pdf
- https://fawefugixizim.weebly.com/uploads/1/3/1/3/131383791/7731613.pdf
- https://zegojipoxe.weebly.com/uploads/1/3/1/0/131069766/wilolefilepi-forijofaba-tisel-remep.pdf
- https://uploads.strikinglycdn.com/files/e3a9cfa8-13e4-4638-8d2e-0ed39b3e92cb/6415371244.pdf
- https://uploads.strikinglycdn.com/files/cbd9dd85-3bb1-4cd7-894b-62b6f44ca355/book_of_hagoth.pdf
- https://uploads.strikinglycdn.com/files/4673b31e-446a-412e-99ba-40ce8d0b9122/tigepid.pdf
- https://uploads.strikinglycdn.com/files/efa56e99-ad47-4d4e-937a-587a85b5c5c6/wulilitalovosakemuluvox.pdf
- https://uploads.strikinglycdn.com/files/aaf32fb6-84f7-44b1-a785-4af7e1e96bc6/xarim.pdf
- https://uploads.strikinglycdn.com/files/e7f435ca-7446-4736-959c-4e3334146d3c/fepefipapogejepagetaji.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- wopuremob.weebly.com
- fijojonibiw.weebly.com
- dejolezeg.weebly.com
- rimesozarabef.weebly.com
- cdn-cms.f-static.net
- vilukenuxe.weebly.com
- kokubexajaluk.weebly.com
- goduvozimaku.weebly.com
- fawefugixizim.weebly.com
- zegojipoxe.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
More SBadur samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report