MALICIOUS — 1715bf_3e2ee4f334bb4ab1ab01823dd6fe8bef.pdf
MALICIOUS — 1715bf_3e2ee4f334bb4ab1ab01823dd6fe8bef.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1c4348cc609b08411f5bb09ed899d1a4429ebddc58c503249064c481aa028701 - SHA-1:
43731e54f03dc98c691daa7c103dee941a89d4e7 - MD5:
053c57860c5e6797fd5316309c39b8b5 - ssdeep:
768:AgGzpDIQRPI2AR9FKV+OWU5M5rNeQOQw0AlLsHHY6kIIBo:NGFkQMFK4OWU5M5jORiY6kIIBo - TLSH:
T1BF319EF35097ECCC76CB6F47AEE615986086D3896077ABA0058C762CC4787EDAF40522 - Submitted as: 1715bf_3e2ee4f334bb4ab1ab01823dd6fe8bef.pdf
- File type: pdf · Size: 40118 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.PDF.Agent.gen (rule
HEUR:Trojan.PDF.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=illuminati+mlg+soundboard+apk, https://3d438a88-385d-483c-a616-cbd4c6e2b940.filesusr.com/ugd/3d0627_f803351745d84990870b0736ccbacbbe.pdf?index=true, https://61e95172-2cfe-4193-8ba8-341996dae8ac.filesusr.com/ugd/5f5755_6d2d8437e4ee434baec44c3b0d278532.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
1004 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- searchapp.bundleassets.example
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- staging.to-do.officeppe.com
- m365.cloud.microsoft
- ntp.ubuntu.com
- 192.168.122.105
- 224.0.0.252
- 192.168.122.1
- 192.168.122.255
- 192.168.122.113
- 192.168.122.115
- 192.168.122.106
- 192.168.122.108
- 192.168.122.114
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ttraff.ru/wix?keyword=illuminati+mlg+soundboard+apk
- https://3d438a88-385d-483c-a616-cbd4c6e2b940.filesusr.com/ugd/3d0627_f803351745d84990870b0736ccbacbbe.pdf?index=true
- https://61e95172-2cfe-4193-8ba8-341996dae8ac.filesusr.com/ugd/5f5755_6d2d8437e4ee434baec44c3b0d278532.pdf?index=true
- https://d780874b-0603-4eb7-a96b-8875614f3525.filesusr.com/ugd/e6092c_917c33da170842beb4ebd80bcdbf798b.pdf?index=true
- https://c1f57335-d495-45e2-a142-5b87ce71fa00.filesusr.com/ugd/0a51c1_ffa0cd4ce53c40d798ae4843ef3d0f2b.pdf?index=true
- https://91d02b1c-126e-40fa-8e65-3047f8c52d9e.filesusr.com/ugd/1e557c_706992cd1d1e453cbecbf57c20b32704.pdf?index=true
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/88075317933.pdf
- https://cdn.shopify.com/s/files/1/0465/0873/6662/files/81239044297.pdf
- https://cdn.shopify.com/s/files/1/0427/9474/6023/files/pusorebebe.pdf
- http://marowovo.drinessamanevich.com/uploads/1/3/2/6/132682859/winejusux-likexepukuzu-dazazipibosuv-vefek.pdf
- http://files.greatwhiteninja.com/uploads/1/3/1/6/131636946/nowur-zobosuw-jimovutamoweji-pekigafis.pdf
- http://files.combatveteranswithptsd.org/uploads/1/3/1/6/131606431/panixoj-gajiponutojemo.pdf
- https://719bf4d0-d17e-4c47-b786-cd9f91d73ee8.filesusr.com/ugd/ccf397_8a88c6cce7d34530a80d8819290b56e5.pdf?index=true
- https://75f9f60a-02f4-4771-b220-81a838b44c52.filesusr.com/ugd/5926b4_302baf477b62405db6663dbabd2472fa.pdf?index=true
- https://60d67809-7f6f-4c92-94fc-87b5948c9609.filesusr.com/ugd/1decf9_9b967180ac064979abfac889e89e3e35.pdf?index=true
- https://2f52663d-2e0b-4056-8f42-e4bc63fa2c2d.filesusr.com/ugd/54fa57_d54903fa835d4eefb64536615eaa1f23.pdf?index=true
- https://d78af063-3203-4b62-b034-5a2a36a02ccc.filesusr.com/ugd/a8ca0f_a2d069ed4ec2475f9a6ff51005b195f2.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- 3d438a88-385d-483c-a616-cbd4c6e2b940.filesusr.com
- 61e95172-2cfe-4193-8ba8-341996dae8ac.filesusr.com
- d780874b-0603-4eb7-a96b-8875614f3525.filesusr.com
- c1f57335-d495-45e2-a142-5b87ce71fa00.filesusr.com
- 91d02b1c-126e-40fa-8e65-3047f8c52d9e.filesusr.com
- cdn.shopify.com
- marowovo.drinessamanevich.com
- files.greatwhiteninja.com
- files.combatveteranswithptsd.org
- 719bf4d0-d17e-4c47-b786-cd9f91d73ee8.filesusr.com
- 75f9f60a-02f4-4771-b220-81a838b44c52.filesusr.com
- 60d67809-7f6f-4c92-94fc-87b5948c9609.filesusr.com
- 2f52663d-2e0b-4056-8f42-e4bc63fa2c2d.filesusr.com
- d78af063-3203-4b62-b034-5a2a36a02ccc.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report