MALICIOUS — vodulufoziverifuwepijid.pdf
MALICIOUS — vodulufoziverifuwepijid.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
407f74c0114612b39c83eaf0a93583eaabf9cb6bb495142a0024b537195e304b - SHA-1:
d24b73ba19c0a84b91f334ade29217f00f2a4ef9 - MD5:
5c889063b80d03752d8ad5b46860829b - ssdeep:
768:ogGzpDRnrxoup6Sc888888888888888888888888/tRyzqPzligcWPBzYGwhN+3:lGFtVXcScmz0ogcWhYGwL+3 - TLSH:
T18D349EF360A3DE8C7BC6DFC369AB146DB54AD2892122976444D87BACC4783BD6F00950 - Submitted as: vodulufoziverifuwepijid.pdf
- File type: pdf · Size: 53108 bytes
- Verdict: malicious (86/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 86/100 is the fusion of 7 weighted signals:
- Memory forensics: 4 finding(s), e.g. RWX/private injected region in SumatraPDF.exe (pid 8688) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Contacted 18 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/9d8ef062-5107-46ff-a576-153a6829462d/kapotagorijenew.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=ni%25C3%25B1o+chiquitico+quiero+que+me+traiga, https://uploads.strikinglycdn.com/files/9d8ef062-5107-46ff-a576-153a6829462d/kapotagorijenew.pdf, https://uploads.strikinglycdn.com/files/254b11d1-b26a-454b-96f7-db39584fd5d4/54484862737.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9645 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 250.255.255.239.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 255.255.254.169.in-addr.arpa
- 79.243.254.169.in-addr.arpa
- 251.0.0.224.in-addr.arpa
- ntp.ubuntu.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
281a60a1f301b82b692c5253900b5ecb347c15d8e70ef05bab1b4ad02a9f4293 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\6b5d2f91e04f2b64aac29970d27ccdd2.png -
27f0343d27f1b79d00223dc8aa1e9fdd1a7bc93c75a65514a31dcf92143ccfd4 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://cctraff.ru/strik?keyword=ni%25C3%25B1o+chiquitico+quiero+que+me+traiga
- https://uploads.strikinglycdn.com/files/9d8ef062-5107-46ff-a576-153a6829462d/kapotagorijenew.pdf
- https://uploads.strikinglycdn.com/files/254b11d1-b26a-454b-96f7-db39584fd5d4/54484862737.pdf
- https://uploads.strikinglycdn.com/files/88012991-a61b-4c03-9b91-7e8c24550da8/kilonikovotesure.pdf
- https://uploads.strikinglycdn.com/files/165db66e-9e62-446f-857a-7110a0739365/nidonasijogasiwa.pdf
- http://files.daphnelunge.com/uploads/1/3/2/8/132814448/02d3606c34832b6.pdf
- http://sopopazid.sthrouda.com/uploads/1/3/0/7/130775755/laraviwelogaxijazimu.pdf
- http://sakog.civilwarlady.net/uploads/1/3/1/3/131379182/raxokutavufamisuvo.pdf
- http://files.teegravy.store/uploads/1/3/2/6/132695489/8b031c6.pdf
- http://modokaga.47fullerroad.com/uploads/1/3/0/8/130814328/bowavuwo.pdf
- https://site-1040175.mozfiles.com/files/1040175/jufupamokumisematazi.pdf
- https://site-1039493.mozfiles.com/files/1039493/totuwixomixuzapimomarepu.pdf
- https://site-1042016.mozfiles.com/files/1042016/miwagedaxuxiri.pdf
- https://site-1036695.mozfiles.com/files/1036695/93916132622.pdf
- https://site-1036733.mozfiles.com/files/1036733/93571128268.pdf
- http://files.hopestateliving.com/uploads/1/3/1/6/131606733/79e92a110b6377f.pdf
- http://mijerisu.everythingisnecessary.com/uploads/1/3/2/7/132741269/6265031.pdf
- http://files.cobbuildingwithmaya.com/uploads/1/3/0/7/130775828/9d83f73b9.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- files.daphnelunge.com
- sopopazid.sthrouda.com
- sakog.civilwarlady.net
- files.teegravy.store
- modokaga.47fullerroad.com
- site-1040175.mozfiles.com
- site-1039493.mozfiles.com
- site-1042016.mozfiles.com
- site-1036695.mozfiles.com
- site-1036733.mozfiles.com
- files.hopestateliving.com
- mijerisu.everythingisnecessary.com
- files.cobbuildingwithmaya.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 74.179.71.159
- 40.84.85.40
- 85.210.196.11
- 20.89.1.9
- 172.172.255.216
- 4.155.89.87
- 52.110.12.45
- 4.230.171.124
- 135.232.92.137
- 74.178.240.51
- 52.123.128.14
- 52.178.17.233
- 203.26.79.13
- 135.233.95.144
- 52.123.252.195
- 74.178.76.44
- 135.234.160.244
- 48.192.143.121
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report