MALICIOUS — samupekawi.pdf
MALICIOUS — samupekawi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the SBadur family. 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6fc9a16de73a413fc8e8704aa56f2b9ee36a03c83ba30e0e8b8cdb0e3bb07d9e - SHA-1:
16a8b796b58865c43ec0d7ceaac741bd6a887b15 - MD5:
0a8e4c03c1aa3b30d358d1b6032e2fa2 - ssdeep:
768:VgGzpD8pe8pOPPkZZwwQ16/yTunydisGWhdM0nZIAN5Z3+wPFp/2atAsT51ICj:GGFYp1Tydis711N5NVeJ+1ICj - TLSH:
T19D329DF350A7ED4E7B8B6F53ADAB005E5588C2887126D390148CB62CD5BC2BEBF11451 - Submitted as: samupekawi.pdf
- File type: pdf · Size: 44118 bytes
- Verdict: malicious (87/100) · Family: SBadur
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 87/100 is the fusion of 5 weighted signals:
- Embedded link rated malicious by URL analysis: https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/4643970e.pdf - network signal, weight 0.70, confidence 0.80
- Kaspersky (KVRT) flagged UDS:Trojan.PDF.SBadur.gen (rule
UDS:Trojan.PDF.SBadur.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://cctraff.ru/wb?keyword=calcular%20fuerza%20resultante, https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/4643970e.pdf, https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/kadupe_ripovu_jozovagazemewe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=calcular%20fuerza%20resultante
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/4643970e.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/kadupe_ripovu_jozovagazemewe.pdf
- https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/8252373.pdf
- https://cdn.shopify.com/s/files/1/0430/8641/3985/files/mobapesamo.pdf
- https://uploads.strikinglycdn.com/files/3e241f32-b30e-4e8a-92e1-6ddc94fb17e7/86049070061.pdf
- https://uploads.strikinglycdn.com/files/6a1ad55e-ad13-4ee3-af45-cf96b2e756ee/86468085151.pdf
- https://uploads.strikinglycdn.com/files/28103288-040b-414e-adb4-9df3648581c9/92952347438.pdf
- https://cdn.shopify.com/s/files/1/0430/5282/6777/files/blazing_saddles_full_movie_online_free.pdf
- https://cdn.shopify.com/s/files/1/0503/3358/1462/files/25857884269.pdf
- https://cdn.shopify.com/s/files/1/0437/2224/4264/files/the_curious_writer_4th_edition.pdf
- https://cdn-cms.f-static.net/uploads/4366324/normal_5f8718166d966.pdf
- https://cdn-cms.f-static.net/uploads/4366348/normal_5f87846c1320f.pdf
- https://cdn-cms.f-static.net/uploads/4369168/normal_5f87fbf6c0efb.pdf
- https://cdn-cms.f-static.net/uploads/4374980/normal_5f8a67b809536.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f874320bf22c.pdf
- https://cdn.shopify.com/s/files/1/0483/8896/4503/files/763053039.pdf
- https://cdn.shopify.com/s/files/1/0497/3366/4919/files/minecraft_ghost_mod.pdf
- https://cdn.shopify.com/s/files/1/0438/8087/4139/files/5855335300.pdf
- https://cdn.shopify.com/s/files/1/0484/8176/3483/files/6536549714.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- megadezatesaram.weebly.com
- gimejexoxixaza.weebly.com
- jawowigo.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
More SBadur samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report