MALICIOUS — witumavililumaposoxu.pdf
MALICIOUS — witumavililumaposoxu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4d84d6a0a2251683fdcfb9ce23fefa6e4e8c659d9947a9e3b597f16af97e8c8e - SHA-1:
8316db00a2a74e4f04eadc3f190378a8ca67846b - MD5:
fb375eb08b1553233f1f233d44788906 - ssdeep:
768:ugGzpDDMrfRkDZ2HCtVFDpiWAWVZBcM/EjUJQsWCQuEKr+mKQu3i0Wg4XlPWlIWQ:LGFPXiWAWVZ3/ECQFuEoKlulP2ITP - TLSH:
T131329EF32057EC8C66CBAB03ACFB0515614A8B8C7236A694159C7B7CD4BC2BD7E10A51 - Submitted as: witumavililumaposoxu.pdf
- File type: pdf · Size: 45472 bytes
- Verdict: malicious (86/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 86/100 is the fusion of 7 weighted signals:
- Memory forensics: 3 finding(s), e.g. RWX/private injected region in SumatraPDF.exe (pid 6092) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Contacted 33 external host(s) at runtime (27 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: http://files.lutherancampusministrywwu.com/uploads/1/3/2/6/132681946/kasakebuzozasiduzig.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=cisco+itn+chapter+9+exam+answers, http://files.lutherancampusministrywwu.com/uploads/1/3/2/6/132681946/kasakebuzozasiduzig.pdf, http://gowefib.thorsonpto.org/uploads/1/3/2/6/132696067/9dc36ecc91.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (8 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
8723 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\caaba6165a9a5bf8c922eb94ef1bc23f.png -
384b5cb5aabadf76ef222b1ac16c0bc76443b6f5d6c5ae74369782ff1a74cfe6 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
435abe006f06ca39201003768070821c13bfa793a38514dcd458888dfeae7edb
Embedded URLs
- https://ggtraff.ru/strik?keyword=cisco+itn+chapter+9+exam+answers
- http://files.lutherancampusministrywwu.com/uploads/1/3/2/6/132681946/kasakebuzozasiduzig.pdf
- http://gowefib.thorsonpto.org/uploads/1/3/2/6/132696067/9dc36ecc91.pdf
- http://files.crossroadsconsultinginc.com/uploads/1/3/1/3/131379696/3ee84f4a89.pdf
- https://uploads.strikinglycdn.com/files/01e305bb-0cf0-4f56-bc29-b67664476977/xuxekokogatowupaninuze.pdf
- https://uploads.strikinglycdn.com/files/84f8b6db-5d96-43c8-b6d0-73e80ec34b28/zuvunufukemax.pdf
- https://cdn.shopify.com/s/files/1/0501/6272/9125/files/cedar_lake_campground_map.pdf
- https://cdn.shopify.com/s/files/1/0438/9945/3608/files/sivefafa.pdf
- https://cdn.shopify.com/s/files/1/0462/6251/7909/files/zowabidinivipuk.pdf
- https://cdn.shopify.com/s/files/1/0433/4521/5637/files/61555261531.pdf
- https://cdn.shopify.com/s/files/1/0483/4164/7523/files/how_to_calculate_the_average_atomic_mass_for_isotopes.pdf
- https://uploads.strikinglycdn.com/files/e4cb4db4-d5f7-42ea-9f12-09d22d6331a5/pizile.pdf
- https://uploads.strikinglycdn.com/files/801ee2b5-e9d9-4828-be78-16e81e1fd920/tatiwefilepatu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787759995&P2=404&P3=2&P4=Fk1qgvZJ1QYGCJaq3S1fPQ72IKBtOrjb5qQk5ILvfPq%2fNpCON30e3uHFBzvAAfg97bmqjb47tP%2bkV8oiw2883Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Embedded domains
- ggtraff.ru
- files.lutherancampusministrywwu.com
- gowefib.thorsonpto.org
- files.crossroadsconsultinginc.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
- oneclient.sfx.ms
Embedded IP addresses
- 20.165.94.46
- 52.123.252.229
- 20.42.73.25
- 4.230.171.124
- 57.154.63.210
- 4.155.89.87
- 135.233.95.144
- 52.182.141.63
- 74.178.240.51
- 135.232.92.137
- 20.231.239.246
- 40.99.133.242
- 52.123.128.14
- 52.123.129.14
- 51.105.71.136
- 203.26.79.13
- 74.178.76.44
- 172.178.240.163
- 4.247.188.224
- 57.155.101.212
- 52.148.114.188
- 48.200.63.27
- 92.223.78.30
- 72.154.7.106
- 48.192.143.121
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report