MALICIOUS — b43669f2c.pdf
MALICIOUS — b43669f2c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100). 3 of 50 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
0abdd5988b871bc502c1af33a3ab81e3682d120e164c6e05f7e35c554c675b9a - SHA-1:
75ec83435966ed923b158acb7702ffea9b70a03d - MD5:
a75b37933dc671f6439ff0d8c2fa4e07 - ssdeep:
768:VgGzpD3pKKYSoyiUSM3LwQpMU5Mo+i+VWKmNnIfQ61plLf2eV7rd4T8kXYQ:GGFTpmJFE72o5eWKmNnIoelLueV7568M - TLSH:
T1C9328DF71097EC4C7A8A9F03ADFA1099518AE3887237976018AC776CC47C6AD6E10D61 - Submitted as: b43669f2c.pdf
- File type: pdf · Size: 45025 bytes
- Verdict: malicious (86/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 86/100 is the fusion of 7 weighted signals:
- Embedded link rated malicious by URL analysis: https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/wirexanusir.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 24 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=rush%202049%20arcade, https://uploads.strikinglycdn.com/files/8ee17042-f872-4944-9160-1118f5a879cd/54285049023.pdf, https://uploads.strikinglycdn.com/files/76c08bc7-8328-442a-b73b-4d8163b5dbdf/xadipovo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9619 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- c.pki.goog
- desktop-hsgcbep
- 255.255.254.169.in-addr.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 251.0.0.224.in-addr.arpa
- 252.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
Dropped files
- /opt/CAPEv2/storage/analyses/38467/files/35c0c9c1d25b003fde7937a9cb2514bff527e6fa02ae86d0b819ecade8fc5594 -
35c0c9c1d25b003fde7937a9cb2514bff527e6fa02ae86d0b819ecade8fc5594 - /opt/CAPEv2/storage/analyses/38467/files/f31ece5293a576827829660886cb97736357af9161cc919d1ec08638894b311f -
f31ece5293a576827829660886cb97736357af9161cc919d1ec08638894b311f - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://gettraff.ru/wb?keyword=rush%202049%20arcade
- https://uploads.strikinglycdn.com/files/8ee17042-f872-4944-9160-1118f5a879cd/54285049023.pdf
- https://uploads.strikinglycdn.com/files/76c08bc7-8328-442a-b73b-4d8163b5dbdf/xadipovo.pdf
- https://uploads.strikinglycdn.com/files/b96dbcb0-f39c-4bd5-b949-1dd383b5399d/nevizajupomigutefuvov.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/wirexanusir.pdf
- https://jonukejunuxesa.weebly.com/uploads/1/3/1/4/131409236/jelatokik-rikusabopogopi-gapigiwe.pdf
- https://xikosenazegan.weebly.com/uploads/1/3/0/7/130739601/d08ea.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/665612.pdf
- https://uploads.strikinglycdn.com/files/6a04801e-ea49-4c27-98b6-8757eea1f4ad/59277878624.pdf
- https://uploads.strikinglycdn.com/files/e3490383-252c-4753-a847-474955c7a775/14385175885.pdf
- https://uploads.strikinglycdn.com/files/af551222-16fb-4f5a-9030-876116a5ce7b/zogefevu.pdf
- https://uploads.strikinglycdn.com/files/41439f8a-4297-4b53-be88-66f11f4f55a1/89846121437.pdf
- https://uploads.strikinglycdn.com/files/1cdc4f09-de65-4efb-98e7-6d370ac54951/xotefalubobovul.pdf
- https://cdn.shopify.com/s/files/1/0493/9651/4972/files/best_camping_tents_walmart.pdf
- https://cdn.shopify.com/s/files/1/0475/1776/1702/files/46154075539.pdf
- https://sibakixode.weebly.com/uploads/1/3/2/8/132814768/puwep-jusulanafuro.pdf
- https://nogafuku.weebly.com/uploads/1/3/2/8/132815296/7596933.pdf
- https://pepuzategazeg.weebly.com/uploads/1/3/1/4/131453576/ronifovujaki-vexof-sepaloten-ledaxibojerumo.pdf
- https://cdn-cms.f-static.net/uploads/4372696/normal_5f88b9e664539.pdf
- https://cdn-cms.f-static.net/uploads/4369646/normal_5f890a0b3c662.pdf
- https://cdn-cms.f-static.net/uploads/4369633/normal_5f88803ba352d.pdf
- https://cdn-cms.f-static.net/uploads/4367000/normal_5f879b07ed596.pdf
- https://cdn-cms.f-static.net/uploads/4369503/normal_5f88c57da26d7.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- fijojonibiw.weebly.com
- jonukejunuxesa.weebly.com
- xikosenazegan.weebly.com
- dutitujazekap.weebly.com
- cdn.shopify.com
- sibakixode.weebly.com
- nogafuku.weebly.com
- pepuzategazeg.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.168.117.171
- 4.150.223.111
- 40.79.150.121
- 172.172.255.218
- 4.150.223.106
- 4.150.223.104
- 52.182.143.212
- 20.184.175.21
- 52.168.117.168
- 20.42.179.192
- 4.230.171.124
- 20.247.184.197
- 20.184.175.20
- 74.178.76.128
- 52.123.129.14
- 40.99.133.242
- 135.234.160.246
- 135.232.92.34
- 203.26.79.13
- 52.123.252.197
- 172.217.25.163
- 135.233.95.144
- 135.234.160.245
- 172.170.180.133
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report