MALICIOUS — 96822962026.pdf
MALICIOUS — 96822962026.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
1f37942898174284b101bb1a114881d5c97502034b1bcc58345d5fa73b3397b3 - SHA-1:
b1b6562364975fc5d2fc9d12bc0469313fa35f7f - MD5:
299e1607832e424bc98a3e94b7c59119 - ssdeep:
768:s+gGzpDqe9WXfP/Q+FzCQmDbF8LVxIB3S+FTAtS2I1rMTamYFyurxrP:6GFmeQHBHmH7igTAYprM+FfrxrP - TLSH:
T19634AFF31097ED8C7A8BBF475FEB1099245AC689113693A005CC763DC4BC5AC6E10E65 - Submitted as: 96822962026.pdf
- File type: pdf · Size: 52636 bytes
- Verdict: malicious (72/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 72/100 is the fusion of 6 weighted signals:
- Contacted 18 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/5818cc3c-6292-48c9-b2b6-8bd3cfb4288c/2985745640.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=relative+layout+android+studio+3.4, https://uploads.strikinglycdn.com/files/5818cc3c-6292-48c9-b2b6-8bd3cfb4288c/2985745640.pdf, https://uploads.strikinglycdn.com/files/fb9379a3-a68d-4641-98a1-ef238c3cc493/35430488050.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (17 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9806 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- _dosvc._tcp.local
- desktop-hsgcbep._dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\b085c764994b74035ff131384bda132e.png -
b975e1fa236fb8aeb7150f182b8b8a0b6c4d620c360c995718b73a0a70fe83fa - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
e337d0a5aab8a0a934be2b36a01e4a0462723f2ba2e154e1f01c8657e2129b0e - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ggtraff.ru/strik?keyword=relative+layout+android+studio+3.4
- https://uploads.strikinglycdn.com/files/5818cc3c-6292-48c9-b2b6-8bd3cfb4288c/2985745640.pdf
- https://uploads.strikinglycdn.com/files/fb9379a3-a68d-4641-98a1-ef238c3cc493/35430488050.pdf
- https://uploads.strikinglycdn.com/files/056709da-ed8c-4101-9d4e-34d4d33c576a/56797642815.pdf
- http://files.cowaysyahila.com/uploads/1/3/1/3/131380128/5997361.pdf
- http://files.asiaticofusion.net/uploads/1/3/2/6/132682093/meguperuriganiv_bemonezuk_kuratovejotuwe.pdf
- http://fixape.franco-british-society.org/uploads/1/3/1/6/131637372/kafuvukuviru.pdf
- https://uploads.strikinglycdn.com/files/cffbb8cd-88f2-4632-86cd-9bc2981f33b8/jupatubuzuvebupibaf.pdf
- https://uploads.strikinglycdn.com/files/9f7878dc-3cbc-470c-bd30-76ec41580eb9/poselimewalado.pdf
- https://uploads.strikinglycdn.com/files/bcaf2c01-845c-4e64-9979-ffeb1aa93b03/veruzexu.pdf
- https://uploads.strikinglycdn.com/files/70b0d85b-47b8-4999-ab9b-e8dd44618762/91417290858.pdf
- https://uploads.strikinglycdn.com/files/deae2ee8-e4d3-4a80-aa22-d06ff20981bc/87309612319.pdf
- https://uploads.strikinglycdn.com/files/adc8c187-fe57-4d0d-94a0-a18bc59416ed/95203791814.pdf
- https://uploads.strikinglycdn.com/files/80dfada3-1731-485e-937a-ef20c1c13936/dubogekazonuforode.pdf
- https://uploads.strikinglycdn.com/files/472879df-f1f5-4896-9c59-2291e1cef02e/24267270619.pdf
- https://uploads.strikinglycdn.com/files/4b92f57d-c5ac-40c3-b8ad-ec91d3a5a9c9/29232471861.pdf
- https://uploads.strikinglycdn.com/files/9b6c36d6-b66b-4649-88fb-26d68f67bbc4/lovibumuwabulegenimi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- files.cowaysyahila.com
- files.asiaticofusion.net
- fixape.franco-british-society.org
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 172.172.255.218
- 20.42.179.204
- 52.110.12.25
- 4.230.171.124
- 20.247.184.197
- 20.165.94.63
- 74.178.240.51
- 20.112.250.133
- 52.123.129.14
- 135.233.95.80
- 203.26.79.13
- 135.233.45.223
- 57.155.104.224
- 104.46.162.231
- 172.175.111.170
- 4.150.223.109
- 52.148.114.188
- 172.217.25.195
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report