MALICIOUS — 68f148888da839.pdf
MALICIOUS — 68f148888da839.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the SBadur family. 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f99082c142737984d0601b5ab90641146910eacf9a7d0cf59f9835e26db63128 - SHA-1:
dceef709afd51dae31883e784fba17f71f118b94 - MD5:
c77beeddf629411a877dfe85cb26d115 - ssdeep:
768:bqgGzpDAeP7FERi1f+VFc15TwqeF/Pl464kcDP3BfItwJ40i95y8nab:bGFkeTj0r4kcDP3BfIE40i9fnab - TLSH:
T107329DF310D7EC9C66CEAB479DB7115EA14AD7892136C6A0444C7B2CC97C2BDAE00E21 - Submitted as: 68f148888da839.pdf
- File type: pdf · Size: 46245 bytes
- Verdict: malicious (87/100) · Family: SBadur
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 87/100 is the fusion of 5 weighted signals:
- Embedded link rated malicious by URL analysis: https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/mofep.pdf - network signal, weight 0.70, confidence 0.80
- Kaspersky (KVRT) flagged UDS:Trojan.PDF.SBadur.gen (rule
UDS:Trojan.PDF.SBadur.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://cctraff.ru/wb?keyword=the%20story%20and%20its%20writer%2010th%20edition, https://uploads.strikinglycdn.com/files/01e15eca-42f6-49dd-878f-7d33567e0e44/84104715840.pdf, https://uploads.strikinglycdn.com/files/3113e617-35da-4075-b752-cb55d70ee6e3/40457940625.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=the%20story%20and%20its%20writer%2010th%20edition
- https://uploads.strikinglycdn.com/files/01e15eca-42f6-49dd-878f-7d33567e0e44/84104715840.pdf
- https://uploads.strikinglycdn.com/files/3113e617-35da-4075-b752-cb55d70ee6e3/40457940625.pdf
- https://uploads.strikinglycdn.com/files/36132a2f-025b-441a-85ac-b1329075de07/kepevawudavi.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/mofep.pdf
- https://zafozudakajadev.weebly.com/uploads/1/3/0/8/130814863/xujewonagamaxu.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/pabagugiridepoluwaru.pdf
- https://loguxofe.weebly.com/uploads/1/3/0/7/130775118/3331982.pdf
- https://nukevokisoget.weebly.com/uploads/1/3/2/7/132711970/xazumaziz_wafozuzofati.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/1d1f8ecc085ca.pdf
- https://kupugaxome.weebly.com/uploads/1/3/0/9/130969415/9078787.pdf
- https://cdn.shopify.com/s/files/1/0492/8189/2509/files/arkham_asylum_a_serious_house_on_serious_earth_hardcover.pdf
- https://cdn.shopify.com/s/files/1/0484/1141/0590/files/kenilworth_junior_high_school_edmonton.pdf
- https://cdn.shopify.com/s/files/1/0476/7350/8006/files/romofizefezomizena.pdf
- https://cdn.shopify.com/s/files/1/0397/9332/8315/files/38321542836.pdf
- https://cdn.shopify.com/s/files/1/0482/1168/9629/files/17509428919.pdf
- https://cdn.shopify.com/s/files/1/0482/1129/6410/files/minecraft_1.8_iron_trapdoor_recipe.pdf
- https://cdn.shopify.com/s/files/1/0501/0024/0541/files/tiger_arcade_emulator_android.pdf
- https://uploads.strikinglycdn.com/files/4b019d33-5afa-4111-a8d0-aa4bca533f24/julefokuli.pdf
- https://uploads.strikinglycdn.com/files/ab8516db-1667-4ce7-bf67-3f7d33f191eb/kutejuluni.pdf
- https://uploads.strikinglycdn.com/files/b30eddd5-afe0-4718-94ff-9336e1154b65/guvikorososinot.pdf
- https://uploads.strikinglycdn.com/files/ab418fcc-3140-4c8c-8b62-21b65d5dc9ab/xozepamupenaduxememopam.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- guwomenod.weebly.com
- zafozudakajadev.weebly.com
- xojerajap.weebly.com
- loguxofe.weebly.com
- nukevokisoget.weebly.com
- mogilifus.weebly.com
- kupugaxome.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
More SBadur samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report