MALICIOUS — 1ece1.pdf
MALICIOUS — 1ece1.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the SBadur family. 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d0761c4d918f5fc0f009cc1f93cd6c497fcb326fe998822b81f61ec9e4d4df77 - SHA-1:
295e46fdd06ecb2f92c6003537331ab6d60560c2 - MD5:
9b43b09ca9f66dd0db2d2cfd6c724271 - ssdeep:
768:EgGzpDYpiltv5LnHut+x63R1ZTt9GXiC0XicFnvIsJQz3b+BbCKphRF3YI5:xGF8pXTuX4r5xab+JCKtl5 - TLSH:
T11E328CF71097EE4C7ACB8B13ADEB256A550DC38861379360418C7B2DD8BC6AD7E50860 - Submitted as: 1ece1.pdf
- File type: pdf · Size: 43784 bytes
- Verdict: malicious (87/100) · Family: SBadur
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 87/100 is the fusion of 5 weighted signals:
- Embedded link rated malicious by URL analysis: https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/3257372.pdf - network signal, weight 0.70, confidence 0.80
- Kaspersky (KVRT) flagged UDS:Trojan.PDF.SBadur.gen (rule
UDS:Trojan.PDF.SBadur.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://cctraff.ru/wb?keyword=increase%20speed%20limit, https://cdn-cms.f-static.net/uploads/4374986/normal_5f891b08c70e0.pdf, https://cdn-cms.f-static.net/uploads/4368474/normal_5f877af46eef4.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=increase%20speed%20limit
- https://cdn-cms.f-static.net/uploads/4374986/normal_5f891b08c70e0.pdf
- https://cdn-cms.f-static.net/uploads/4368474/normal_5f877af46eef4.pdf
- https://cdn-cms.f-static.net/uploads/4365551/normal_5f874ae9537b3.pdf
- https://cdn-cms.f-static.net/uploads/4366956/normal_5f87b3523fd1f.pdf
- https://uploads.strikinglycdn.com/files/867866b5-8981-46df-877f-5d7856633be3/suzojuxupobirono.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/3257372.pdf
- https://worobewunit.weebly.com/uploads/1/3/1/4/131406731/4542247.pdf
- https://jewajufigojoxi.weebly.com/uploads/1/3/1/4/131438211/5850180.pdf
- https://xuvakaxatal.weebly.com/uploads/1/3/1/0/131070170/nilofizafogujujuxe.pdf
- https://karezolakep.weebly.com/uploads/1/3/1/3/131398125/vonakikidigis.pdf
- https://cdn-cms.f-static.net/uploads/4366317/normal_5f886f0165aa3.pdf
- https://cdn-cms.f-static.net/uploads/4367624/normal_5f88b21d23dd0.pdf
- https://cdn-cms.f-static.net/uploads/4368219/normal_5f87db8cbb9b3.pdf
- https://cdn-cms.f-static.net/uploads/4366312/normal_5f872ff2989ce.pdf
- https://uploads.strikinglycdn.com/files/785889c5-8878-4f55-947a-aa23d6959c22/dogutatakekunejuze.pdf
- https://uploads.strikinglycdn.com/files/37c645bb-88dc-4b8d-9ad3-19a9a7e3abdd/roguzibulekudo.pdf
- https://uploads.strikinglycdn.com/files/c45c02b3-9618-4ea5-9091-c0d678cb3ddb/bijoxud.pdf
- https://uploads.strikinglycdn.com/files/85c03fc3-1226-4d40-ab52-4e7f8a59dd17/sopugaludulujerefok.pdf
- https://cdn.shopify.com/s/files/1/0482/7915/8948/files/dupalenu.pdf
- https://cdn.shopify.com/s/files/1/0497/4172/5857/files/rijilozawom.pdf
- https://cdn.shopify.com/s/files/1/0433/3119/0952/files/93679174745.pdf
- https://cdn.shopify.com/s/files/1/0433/8666/7158/files/sea_snail_florida.pdf
- https://cdn.shopify.com/s/files/1/0435/4313/4362/files/pobre_ana_in_english_chapter_3.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- vuxozajuje.weebly.com
- worobewunit.weebly.com
- jewajufigojoxi.weebly.com
- xuvakaxatal.weebly.com
- karezolakep.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
More SBadur samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report