SUSPICIOUS — a467527c6684c.pdf
SUSPICIOUS — a467527c6684c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (66/100), attributed to the SBadur family. 2 of 54 detection engines flagged it.
Identification
- SHA-256:
dffbddfcb11194e5dd0374ecae18439736f8ea7f5e1b739fb0d88661bc9c0d00 - SHA-1:
43ddd5cac436533e07734c991eff61d82d03c65b - MD5:
9512899808e2df63f7214714a48093fa - ssdeep:
768:HgGzpDk0nRy3q3kaAtGCcIbu0P2w5/ncAhOFA0g0c2yHY8q19yi6j:AGFQ0I3q3gewd0bg0c2yHY8q1ATj - TLSH:
T19E316DF350E7ED4C7A8B6F07AEA71199944ED789713697A00588272CD0BC6FE7E00A11 - Submitted as: a467527c6684c.pdf
- File type: pdf · Size: 40474 bytes
- Verdict: suspicious (66/100) · Family: SBadur
Detections (2 of 54 engines)
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 66/100 is the fusion of 3 weighted signals:
- Kaspersky (KVRT) flagged UDS:Trojan.PDF.SBadur.gen (rule
UDS:Trojan.PDF.SBadur.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://cctraff.ru/wb?keyword=kitab%20at%20tauhid%20abdul%20wahab%20pdf, https://cdn.shopify.com/s/files/1/0432/6529/4504/files/fraser_fir_tree_size.pdf, https://cdn.shopify.com/s/files/1/0497/3366/4922/files/basic_number_theory.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=kitab%20at%20tauhid%20abdul%20wahab%20pdf
- https://cdn.shopify.com/s/files/1/0432/6529/4504/files/fraser_fir_tree_size.pdf
- https://cdn.shopify.com/s/files/1/0497/3366/4922/files/basic_number_theory.pdf
- https://cdn.shopify.com/s/files/1/0484/0888/7454/files/fujaborifozedutifizu.pdf
- https://cdn-cms.f-static.net/uploads/4366362/normal_5f8a0b8ee7997.pdf
- https://cdn-cms.f-static.net/uploads/4366388/normal_5f875a093b4b8.pdf
- https://cdn-cms.f-static.net/uploads/4371495/normal_5f90625455448.pdf
- https://cdn-cms.f-static.net/uploads/4370072/normal_5f8a762d87aa5.pdf
- https://cdn-cms.f-static.net/uploads/4375076/normal_5f8f37428fa57.pdf
- https://uploads.strikinglycdn.com/files/d897a31e-1e17-420d-b071-0a7b4c300398/ddp_yoga_diet.pdf
- https://uploads.strikinglycdn.com/files/60ee21dc-8a37-4287-91e2-ea2194c44742/vutexopipa.pdf
- https://uploads.strikinglycdn.com/files/2038e049-4a65-41d3-8f24-62ebd2f408c9/mulatekekalepasevixux.pdf
- https://uploads.strikinglycdn.com/files/e8172ba4-0d03-4836-9488-eaf642fd02ff/34042270960.pdf
- https://uploads.strikinglycdn.com/files/f4213b19-9b01-43a5-ab9b-f0fcb30b57b0/pazebodivumo.pdf
- https://uploads.strikinglycdn.com/files/d2b50d92-4588-4836-a3f2-d882e7a9e9c2/como_poner_acento_en_power_point.pdf
- https://uploads.strikinglycdn.com/files/562babca-401f-417a-8411-008e891da406/64517243471.pdf
- https://uploads.strikinglycdn.com/files/73bafec7-f3bd-4809-ae87-3d28be60dfc8/gula_pereduksi.pdf
- https://uploads.strikinglycdn.com/files/27fb169a-200e-438f-917e-29229a943249/4971804874.pdf
- https://uploads.strikinglycdn.com/files/f4cfac89-c77a-4f65-8a86-9afa37f28fb6/33539815326.pdf
- https://uploads.strikinglycdn.com/files/1fe5b0d2-ead1-4838-85ee-6012b1308bfc/25319956772.pdf
- https://uploads.strikinglycdn.com/files/8cb1a2f7-9aaf-4e83-b9f4-34b51ae48911/medicinal_fried_fiasco.pdf
- https://uploads.strikinglycdn.com/files/f7c8c45e-10e0-4ea9-a5f2-95ce144c07ac/oblivion_violin_sheet_music_free.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/9d013.pdf
- https://xukaxikerebata.weebly.com/uploads/1/3/4/0/134042698/davoja.pdf
- https://dokakida.weebly.com/uploads/1/3/1/3/131380589/e22694f3a.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- wepugimi.weebly.com
- xukaxikerebata.weebly.com
- dokakida.weebly.com
- famotufenimuz.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
More SBadur samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report