MALICIOUS — mekidisinamu.pdf
MALICIOUS — mekidisinamu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (77/100), attributed to the SBadur family. 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
de24ecc1fa275721996b3413ef5f9476d756c29ed8d30261307708cd767ce376 - SHA-1:
a11ce82f7574b201fd10130f8751af2e6d0df5fb - MD5:
7a176b7e4f3aa99fbf0030ca70bb4b6c - ssdeep:
1536:rGFCIYKhuCLzyBQh8BC5sRlf4MhtcuzXbC:KFCctzcQh8vfvIuz2 - TLSH:
T13434ADF350C7EE8CBE89AB13ACD711A50649C74D6227A760948DB66CC47C2FDBD508A0 - Submitted as: mekidisinamu.pdf
- File type: pdf · Size: 53936 bytes
- Verdict: malicious (77/100) · Family: SBadur
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 77/100 is the fusion of 5 weighted signals:
- Kaspersky (KVRT) flagged UDS:Trojan.PDF.SBadur.gen (rule
UDS:Trojan.PDF.SBadur.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded link rated suspicious by URL analysis: https://fubomagasikeka.weebly.com/uploads/1/3/4/4/134474343/bosuxufinelexir_lunumir_mapovokorabi.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=clasificacion%20de%20motores%20de%20corriente%20alterna%20pdf, https://xujaxivef.weebly.com/uploads/1/3/1/4/131438557/saselixu_turejokofafip.pdf, https://darurirajilubi.weebly.com/uploads/1/3/4/3/134318819/foxewajoxa_xozexofe_nojijetid_rodevizeb.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=clasificacion%20de%20motores%20de%20corriente%20alterna%20pdf
- https://xujaxivef.weebly.com/uploads/1/3/1/4/131438557/saselixu_turejokofafip.pdf
- https://darurirajilubi.weebly.com/uploads/1/3/4/3/134318819/foxewajoxa_xozexofe_nojijetid_rodevizeb.pdf
- https://dopuxaponaxu.weebly.com/uploads/1/3/2/6/132695391/visosazaxojot_tabug.pdf
- https://pevugubak.weebly.com/uploads/1/3/2/7/132740457/1d3d5152ce.pdf
- https://fubomagasikeka.weebly.com/uploads/1/3/4/4/134474343/bosuxufinelexir_lunumir_mapovokorabi.pdf
- https://sulezesolujoseg.weebly.com/uploads/1/3/1/4/131452841/vurusememiwode-genikejisujukog.pdf
- https://zuwumepegowivos.weebly.com/uploads/1/3/1/0/131069935/8019579.pdf
- https://dofazodasi.weebly.com/uploads/1/3/0/8/130873943/wulonajagopoj.pdf
- https://uploads.strikinglycdn.com/files/41b2562a-f2bb-4c22-b5e7-085969f110f8/tinofarodarovilukudurifi.pdf
- https://uploads.strikinglycdn.com/files/2130faf0-e56a-4608-a1a3-d6ef79e6ade6/54752337970.pdf
- https://uploads.strikinglycdn.com/files/143187be-989c-4619-b4ef-cb7f31784ff3/zokova.pdf
- https://uploads.strikinglycdn.com/files/b7aa37cd-8ab0-432b-96dd-3562fca61451/gewodopobarige.pdf
- https://uploads.strikinglycdn.com/files/db76171e-ecea-42ac-a057-bc985b8652fc/rival_16_qt_roaster_oven_manual.pdf
- https://uploads.strikinglycdn.com/files/67050155-e754-4501-9b60-ab48bf72a0df/gibikukuxe.pdf
- https://uploads.strikinglycdn.com/files/42af984d-4136-4447-b757-bb40266c5a8b/28310649827.pdf
- https://cdn.shopify.com/s/files/1/0480/0387/4967/files/murdoch_mysteries_s12_episode_guide.pdf
- https://cdn.shopify.com/s/files/1/0436/1804/2018/files/tufudadezafojagotebilo.pdf
- https://uploads.strikinglycdn.com/files/5a80ebb0-d7a4-43e5-a04b-6b8aa0caf753/72616264892.pdf
- https://uploads.strikinglycdn.com/files/23d0dd1c-180f-4092-bc0a-4886843f19f3/19718153326.pdf
- https://uploads.strikinglycdn.com/files/9c6abe81-cdab-44fe-9f1c-45bccbbeb78a/furijewobevokan.pdf
- https://uploads.strikinglycdn.com/files/28f632f9-d831-47d3-b08d-0bb470fb5ed0/free_basketball_camp_flyer_template.pdf
- https://uploads.strikinglycdn.com/files/b7b6d1f1-3425-4867-9723-8ae6ae47c7a4/69748014943.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- xujaxivef.weebly.com
- darurirajilubi.weebly.com
- dopuxaponaxu.weebly.com
- pevugubak.weebly.com
- fubomagasikeka.weebly.com
- sulezesolujoseg.weebly.com
- zuwumepegowivos.weebly.com
- dofazodasi.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
More SBadur samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report