MALICIOUS — 2957024.pdf
MALICIOUS — 2957024.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (80/100). 2 of 50 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
3eb827c4586749ef7b27f66554344d96610ed0fd38479ac72cb208c51f55044f - SHA-1:
5b5abe88e7c6b143634ecb8f4426be66124602e2 - MD5:
f4543411d5284a2ac27b397dc2ac559d - ssdeep:
768:9gGzpDUpoTWxPlmdHIKzHwa9E9LHll+C4e4m+2qdwz:+GFYpKPdHIKzHw4aLF6eNqdwz - TLSH:
T1D2329DF354D3ED4CBE8BAB436DA710AA518AC3886233D7A0448D772DC4BC5BD6E11860 - Submitted as: 2957024.pdf
- File type: pdf · Size: 43864 bytes
- Verdict: malicious (80/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 80/100 is the fusion of 7 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/ba74f784-c478-4b0e-82e8-3709a147aeb9/8049789479.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=driver%20safety%20course%20dallas, https://uploads.strikinglycdn.com/files/b6d1b196-f1c0-45a1-8455-fd2f49611b88/19238141479.pdf, https://uploads.strikinglycdn.com/files/d6f3f37b-3492-4c11-8d68-f6a3fa6a3219/natetalorulepiwigejusesu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 7 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9716 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- searchapp.bundleassets.example
- inference.location.live.net
- ntp.ubuntu.com
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep._dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
- 40.126.14.163
- 192.168.122.112
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\c98e386198a4583bdba129fcad8f2e92.png -
41989f5560a2438325b58a67929162bac54d48049d719d9700000bc5b37fd0de - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
6459326682441c34d6c9044a371309d475c92a3f0f4e70af1f572dbe810ed504 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ggtraff.ru/wb?keyword=driver%20safety%20course%20dallas
- https://uploads.strikinglycdn.com/files/b6d1b196-f1c0-45a1-8455-fd2f49611b88/19238141479.pdf
- https://uploads.strikinglycdn.com/files/d6f3f37b-3492-4c11-8d68-f6a3fa6a3219/natetalorulepiwigejusesu.pdf
- https://uploads.strikinglycdn.com/files/7586799e-c619-4956-8442-f47290675117/56084263285.pdf
- https://uploads.strikinglycdn.com/files/749e7816-8a96-4796-b101-a13ccac18fbe/gedimoku.pdf
- https://uploads.strikinglycdn.com/files/ba74f784-c478-4b0e-82e8-3709a147aeb9/8049789479.pdf
- https://site-1037840.mozfiles.com/files/1037840/zonelifukifaf.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/zakeme.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/987b21c6b.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/tunitulo.pdf
- https://cdn-cms.f-static.net/uploads/4366984/normal_5f8738b03e222.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f8706dded5ea.pdf
- https://uploads.strikinglycdn.com/files/a090cbf4-4268-4839-92ec-f329c7ded4d5/44754006495.pdf
- https://uploads.strikinglycdn.com/files/ebdd4590-d5d9-4cd9-80aa-45aee321c672/jakanaritudiduk.pdf
- https://uploads.strikinglycdn.com/files/8ffea374-b7d7-4802-8f98-044f63660f59/39359031478.pdf
- https://uploads.strikinglycdn.com/files/7aad3f39-cefd-4ba3-9825-5779f91ecc2f/nivobi.pdf
- https://uploads.strikinglycdn.com/files/8b299f97-00da-4443-8329-8dd12d343980/defetozasu.pdf
- https://site-1039405.mozfiles.com/files/1039405/15300560673.pdf
- https://site-1043876.mozfiles.com/files/1043876/cisco_ise_tacacs_ordering_guide.pdf
- https://site-1036633.mozfiles.com/files/1036633/73855724211.pdf
- https://site-1039893.mozfiles.com/files/1039893/mifusapapejave.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1037840.mozfiles.com
- dimaxafazeza.weebly.com
- gimejexoxixaza.weebly.com
- dutitujazekap.weebly.com
- cdn-cms.f-static.net
- site-1039405.mozfiles.com
- site-1043876.mozfiles.com
- site-1036633.mozfiles.com
- site-1039893.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 20.42.65.84
- 74.179.77.204
- 135.232.92.97
- 20.112.250.133
- 52.110.12.19
- 162.159.36.2
- 4.230.171.124
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report