MALICIOUS — ac8c68_de69a32ac8db472391f9493e6dc4908a.pdf
MALICIOUS — ac8c68_de69a32ac8db472391f9493e6dc4908a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (80/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
37843446c69eff467ce7f71dfab453ee938a1a34db4e4b7da63c99956edd74d1 - SHA-1:
fe5067b8ef1981193d9b1fcc99e6f44cbc560650 - MD5:
7f129d4761b526dcfc99f5f107efe2b9 - ssdeep:
768:8gGzpDH9ilxcL/oYoWMD9qb3vDP8ZKl5Cfus5Z1aPgZNtK:ZGFr9Rxq+3gZcwf/5Z1aPgZNtK - TLSH:
T1A5318DF3549BEC8C7A8B9B031EAA11492046D68CA236EB741988772DC4BC7BD6F01520 - Submitted as: ac8c68_de69a32ac8db472391f9493e6dc4908a.pdf
- File type: pdf · Size: 41989 bytes
- Verdict: malicious (80/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 80/100 is the fusion of 7 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.me/wix?keyword=download+apk+openvpn+mod, https://2a05e9e6-07fd-4ea1-9c33-bc4c83bfc150.filesusr.com/ugd/3225da_3bd8b32e1cf346e1be09dba7ea37af60.pdf?index=true, https://4024023e-75ea-4804-801d-1530df1fe3a7.filesusr.com/ugd/8c5bc8_6f726a2837b945fb9e1582a7d367f8e6.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 7 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (11 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1009 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- searchapp.bundleassets.example
- teams.cloud.microsoft
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- 23.40.52.85
- 23.11.37.157
- 23.33.238.104
- 20.190.142.163
- 52.123.252.247 AU · Sydney · AS8075 Microsoft Corporation
- 52.110.12.19 AU · Sydney · AS8075 Microsoft Corporation
- 204.79.197.203
- 74.178.76.54 IE · Dublin · AS8075 Microsoft Corporation
- 4.207.44.68 IE · Dublin · AS8075 Microsoft Corporation
- 52.123.129.14 US · Redmond · AS8075 Microsoft Corporation
- 23.33.238.199
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ttraff.me/wix?keyword=download+apk+openvpn+mod
- https://2a05e9e6-07fd-4ea1-9c33-bc4c83bfc150.filesusr.com/ugd/3225da_3bd8b32e1cf346e1be09dba7ea37af60.pdf?index=true
- https://4024023e-75ea-4804-801d-1530df1fe3a7.filesusr.com/ugd/8c5bc8_6f726a2837b945fb9e1582a7d367f8e6.pdf?index=true
- https://211d1ecf-ebbf-4f3c-aca0-b9d0a211acad.filesusr.com/ugd/bcc0e4_54ddb8485e2c436ea761aada587dcd4e.pdf?index=true
- https://cdn.shopify.com/s/files/1/0438/0521/2832/files/mifamisodijoru.pdf
- https://cdn.shopify.com/s/files/1/0439/2619/2283/files/life_insurance_company_balance_sheet_analysis.pdf
- https://cdn.shopify.com/s/files/1/0434/1691/2023/files/873753102.pdf
- https://cdn.shopify.com/s/files/1/0448/4435/1649/files/2014_chevrolet_volt_owners_manual.pdf
- https://cdn.shopify.com/s/files/1/0435/6122/2307/files/mulanaxomewigixotobafowif.pdf
- https://288b053e-6181-465b-8557-0198263118f4.filesusr.com/ugd/6cabbb_4390c6331bf04b11b08f1b3d07b2f3b0.pdf?index=true
- https://df7a2c21-13a1-4929-8e84-9917587d856a.filesusr.com/ugd/565485_8d73ce472e164f8da399624b84be9528.pdf?index=true
- https://ad9c5e27-bb8f-4756-b8ce-e2840fd10e78.filesusr.com/ugd/b361c6_af49a04b66284eb584b189f840f0f165.pdf?index=true
- https://771ca381-6f74-42da-98cb-0a50e62ac45d.filesusr.com/ugd/b9801a_9522c24b7608413188293806cd48796c.pdf?index=true
- https://4c185864-1fba-4209-a122-8f80d50c621c.filesusr.com/ugd/bc0b97_19a8061498f644259eab2d0af2bc79ec.pdf?index=true
- https://fa5801b5-de68-45c9-8e8e-732a82cd1967.filesusr.com/ugd/2c8d66_7921da934e13465cb7f8bbd80eefe14b.pdf?index=true
- https://acd880ec-4189-47f5-b293-78b3010ccd4a.filesusr.com/ugd/668a47_11a07ceb8b2140a68bf0bad8b2ec6b99.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Embedded domains
- ttraff.me
- 2a05e9e6-07fd-4ea1-9c33-bc4c83bfc150.filesusr.com
- 4024023e-75ea-4804-801d-1530df1fe3a7.filesusr.com
- 211d1ecf-ebbf-4f3c-aca0-b9d0a211acad.filesusr.com
- cdn.shopify.com
- 288b053e-6181-465b-8557-0198263118f4.filesusr.com
- df7a2c21-13a1-4929-8e84-9917587d856a.filesusr.com
- ad9c5e27-bb8f-4756-b8ce-e2840fd10e78.filesusr.com
- 771ca381-6f74-42da-98cb-0a50e62ac45d.filesusr.com
- 4c185864-1fba-4209-a122-8f80d50c621c.filesusr.com
- fa5801b5-de68-45c9-8e8e-732a82cd1967.filesusr.com
- acd880ec-4189-47f5-b293-78b3010ccd4a.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.123.252.247
- 52.110.12.19
- 74.178.76.54
- 4.207.44.68
- 52.123.129.14
- 162.159.36.2
- 4.230.171.124
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report