MALICIOUS — 50747041135.pdf
MALICIOUS — 50747041135.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (82/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
3b540dd8b294beecd6c441f2bbe7e10c7b432dd1d1ff74918f688aa76c6b5f5a - SHA-1:
4df5d88ea498f7f156c36871d9377312453da6ad - MD5:
10f6c972e9196719283a80949b8487f2 - ssdeep:
1536:OGFXpzBn1eIcBLbNEOS4L7YvZkvzCktZQy+REQuhK:3FXpFnkD51vKWGkMy+RZR - TLSH:
T1AF38C0F30097ED4CA79D9F536DEB115A6099D28CA0379B90088C7B7CC1BC6BDAE24851 - Submitted as: 50747041135.pdf
- File type: pdf · Size: 78806 bytes
- Verdict: malicious (82/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 82/100 is the fusion of 6 weighted signals:
- Memory forensics: 4 finding(s), e.g. RWX/private injected region in SumatraPDF.exe (pid 3212) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Contacted 29 external host(s) at runtime (25 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=kitgun+riven+mod, https://gumiworawogulaf.weebly.com/uploads/1/3/4/3/134356348/8a1a50b6dc277.pdf, https://sebiwijojemobod.weebly.com/uploads/1/3/4/0/134097571/1508823.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
8820 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\04cd9200cf8c117d0af9b7d88e2b2aa1.png -
2407b7cb373b5997822eea3c56dc2063ff3435b481dd6070e381e1fd81a2c970 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
5e234a84ceecaf22eeaa4cc39bcd301750cb4902a7778040118c187004de3298
Embedded URLs
- https://gettraff.ru/strik?keyword=kitgun+riven+mod
- https://s3.amazonaws.com/jasadavebaga/blouse_cutting_and_stitching_book.pdf
- https://s3.amazonaws.com/fosagoba/airport_runway_markings.pdf
- https://s3.amazonaws.com/pazifetanegapu/arduino_tutorials_point_download_free.pdf
- https://s3.amazonaws.com/bizamesuwepe/ansi_b16._5_class_150_flange_dimensions.pdf
- https://gumiworawogulaf.weebly.com/uploads/1/3/4/3/134356348/8a1a50b6dc277.pdf
- https://sebiwijojemobod.weebly.com/uploads/1/3/4/0/134097571/1508823.pdf
- https://jonukejunuxesa.weebly.com/uploads/1/3/1/4/131409236/6f7ed18f9.pdf
- https://s3.amazonaws.com/wilugugo/nivipufalukuji.pdf
- https://s3.amazonaws.com/zetare/12868035427.pdf
- https://s3.amazonaws.com/loneminovu/89366184834.pdf
- https://s3.amazonaws.com/kavitokolezub/miwanakosadewozus.pdf
- https://s3.amazonaws.com/wukara/advanced_english_vocabulary_with_examples.pdf
- https://s3.amazonaws.com/gofilafixu/78981715263.pdf
- https://s3.amazonaws.com/jupevuxirapi/programme_botola_2020.pdf
- https://s3.amazonaws.com/baxunaf/antonyms_list_with_hindi_meaning_free_download.pdf
- https://s3.amazonaws.com/henghuili-files2/54772777766.pdf
- https://s3.amazonaws.com/tunenijexe/all_information_about_india.pdf
- https://s3.amazonaws.com/tetazino/81785948777.pdf
- https://s3.amazonaws.com/vavabi/public_private_partnership_in_india.pdf
- https://s3.amazonaws.com/tadovu/66932806656.pdf
- https://pufotawimudob.weebly.com/uploads/1/3/4/3/134380049/wibemavodafalimipo.pdf
- https://ditiwudo.weebly.com/uploads/1/3/1/4/131452947/felow.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/kadupe_ripovu_jozovagazemewe.pdf
- https://woliwejimagevin.weebly.com/uploads/1/3/4/3/134319070/5b41b29dc35ea1b.pdf
Embedded domains
- gettraff.ru
- s3.amazonaws.com
- gumiworawogulaf.weebly.com
- sebiwijojemobod.weebly.com
- jonukejunuxesa.weebly.com
- pufotawimudob.weebly.com
- ditiwudo.weebly.com
- gimejexoxixaza.weebly.com
- woliwejimagevin.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 51.104.15.253
- 52.123.252.215
- 4.230.171.124
- 57.154.63.210
- 4.247.188.233
- 20.247.184.142
- 74.178.240.61
- 20.184.175.17
- 135.232.92.97
- 20.76.201.171
- 52.123.129.14
- 40.99.133.210
- 52.168.117.171
- 135.234.160.244
- 52.123.252.233
- 74.179.71.159
- 203.26.79.13
- 52.148.114.188
- 92.223.78.30
- 162.159.142.9
- 20.184.175.16
- 4.209.250.170
- 20.42.65.84
- 4.150.223.97
- 72.153.5.131
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report