MALICIOUS — normal_5f878411d1bc9.pdf
MALICIOUS — normal_5f878411d1bc9.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100), attributed to the SBadur family. 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e95b8eae1b45ea2266c7a151e2f10991cb59f34d87dd10e6d74c174d066e6604 - SHA-1:
985c50b2fdd0380fe5eb35179bcc31b1974ee4ef - MD5:
551197d026116fb7d4928b90f69fa46e - ssdeep:
3072:LGF2pSuu1y9RY/2zMO+xOTRGSqY73Eqma1lsHgAi1bpSK6Qx/teFCoRtKG8RQgk:SAvuKRYezMO+xGGa3EjabSk1bAnQTerV - TLSH:
T19E3FF1F355A7DE8D368787432CAA2159608CC7882611F71541883BBED8FC7BDAE46C60 - Submitted as: normal_5f878411d1bc9.pdf
- File type: pdf · Size: 151035 bytes
- Verdict: malicious (86/100) · Family: SBadur
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 86/100 is the fusion of 7 weighted signals:
- Memory forensics: 3 finding(s), e.g. RWX/private injected region in SumatraPDF.exe (pid 2412) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Contacted 29 external host(s) at runtime (26 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/92e0a66d-351f-49ac-a893-e8587ac0a843/77991414745.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/123?keyword=silencio+administrativo+positivo+peru+pdf, https://cdn.shopify.com/s/files/1/0266/9209/2102/files/nujozetejuj.pdf, https://cdn.shopify.com/s/files/1/0499/9666/0886/files/the_contractor_book_by_raymond_davis.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (6 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
8790 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- c.pki.goog
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\18170a25a09f82d0a6dbec4f8b008902.png -
ff93fb9694aff08f78f0f5f6a501fc121c8210f09d0e60f0abdf02bd9ed20002 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
5526095101c2b117fcc718cbcddcc7f5f7898cf2f0548118595818699a9518ea
Embedded URLs
- https://cctraff.ru/123?keyword=silencio+administrativo+positivo+peru+pdf
- https://cdn.shopify.com/s/files/1/0266/9209/2102/files/nujozetejuj.pdf
- https://cdn.shopify.com/s/files/1/0499/9666/0886/files/the_contractor_book_by_raymond_davis.pdf
- https://cdn.shopify.com/s/files/1/0486/5392/6558/files/58559305961.pdf
- https://cdn.shopify.com/s/files/1/0499/8958/2998/files/reratad.pdf
- https://cdn.shopify.com/s/files/1/0484/2477/9933/files/armitron_pro_sport_watch_instructions.pdf
- https://site-1039892.mozfiles.com/files/1039892/62295068646.pdf
- https://site-1038634.mozfiles.com/files/1038634/lajojinanob.pdf
- https://site-1037121.mozfiles.com/files/1037121/31765251662.pdf
- https://site-1037858.mozfiles.com/files/1037858/rurejawemesugafe.pdf
- https://cdn.shopify.com/s/files/1/0480/9329/8851/files/dryer_fuse_blown.pdf
- https://cdn.shopify.com/s/files/1/0500/5692/1256/files/22961944673.pdf
- https://cdn.shopify.com/s/files/1/0436/4104/5145/files/fikipebo.pdf
- https://cdn.shopify.com/s/files/1/0438/3624/4118/files/the_bad_seed_book_william_march.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/3e75a4e696b2f2d.pdf
- https://rakamukomegu.weebly.com/uploads/1/3/2/6/132681656/bubutowunaj.pdf
- https://fuparududewon.weebly.com/uploads/1/3/1/8/131856041/9897457.pdf
- https://gemaxudemaxepeb.weebly.com/uploads/1/3/1/0/131070646/niwexekeropeveteken.pdf
- https://gusumadanu.weebly.com/uploads/1/3/2/6/132695601/nogewamuvuzoli-kadujuzusuzo-jagebepazo-faposu.pdf
- https://uploads.strikinglycdn.com/files/92e0a66d-351f-49ac-a893-e8587ac0a843/77991414745.pdf
- https://uploads.strikinglycdn.com/files/00a15774-38c8-4314-a68d-e4d4d6291d22/53977682238.pdf
- https://gidixelasulam.weebly.com/uploads/1/3/0/7/130739099/75d76974913a8.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/vanojiraxajerubefiza.pdf
- https://dojulukasinu.weebly.com/uploads/1/3/0/7/130776790/4718221.pdf
- https://mojenosude.weebly.com/uploads/1/3/1/3/131382274/4096502.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- site-1039892.mozfiles.com
- site-1038634.mozfiles.com
- site-1037121.mozfiles.com
- site-1037858.mozfiles.com
- genigudepa.weebly.com
- rakamukomegu.weebly.com
- fuparududewon.weebly.com
- gemaxudemaxepeb.weebly.com
- gusumadanu.weebly.com
- uploads.strikinglycdn.com
- gidixelasulam.weebly.com
- zoxuzuxebexot.weebly.com
- dojulukasinu.weebly.com
- mojenosude.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 4.150.223.115
- 4.230.171.124
- 4.247.188.233
- 20.3.1.41
- 20.165.94.63
- 4.150.223.107
- 74.178.240.51
- 52.123.128.14
- 20.236.44.162
- 40.103.64.226
- 4.207.44.73
- 135.233.95.144
- 74.178.76.44
- 203.26.79.13
- 135.233.45.222
- 57.155.101.212
- 52.148.114.188
- 52.110.12.20
- 104.46.162.230
- 52.168.117.175
- 52.110.12.45
- 72.154.7.102
- 135.233.45.221
- 48.200.63.27
- 20.184.175.20
More SBadur samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report