MALICIOUS — 40766485298.pdf
MALICIOUS — 40766485298.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
54eabb8bb5b756632b6138fa72201e5a2dc5dafc899dccdfbe4f6d834ff4e6f2 - SHA-1:
813ebce6b3e410175287c9e7ff21d22709df69eb - MD5:
74093e2d8b9c71e0306e0553af3e828b - ssdeep:
768:DgGzpDkS5WCmVEIiT4m098hintK07pZ9E8U8ZWcZEyLXdS5wzAjX00:8GFoS4Hp8hintN7pNTZEyLXd3AjX00 - TLSH:
T16232AEF34097DD8D7A8BAB43AE6B0198A149C28D7176936059C9766CC87C6FD3F00A70 - Submitted as: 40766485298.pdf
- File type: pdf · Size: 46261 bytes
- Verdict: malicious (72/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 72/100 is the fusion of 6 weighted signals:
- Contacted 17 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/89e0da90-0674-4cfe-9bfe-d206af7ddb86/52030245380.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=antecedentes+judiciales+certificado+pdf, http://files.coffeynotes.com/uploads/1/3/1/4/131437724/mifevafud-xuninideto-rixujon.pdf, http://lojadurur.ryanlakanen.com/uploads/1/3/2/7/132741508/mazepi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (13 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9796 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- desktop-hsgcbep
- ntp.ubuntu.com
- desktop-hsgcbep._dosvc._tcp.local
- _dosvc._tcp.local
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\6d91fbd2fdd989aba89200f808304214.png -
2253b9075c6bc8c1d1e21726f2eda706b6075f44e5052c246ce0178c4a302521 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
8b4a6eae90686487e9098635bbc40fcd0c9498fee3e2b43ac4a60f6d4d5bf9b2 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://gettraff.ru/strik?keyword=antecedentes+judiciales+certificado+pdf
- http://files.coffeynotes.com/uploads/1/3/1/4/131437724/mifevafud-xuninideto-rixujon.pdf
- http://lojadurur.ryanlakanen.com/uploads/1/3/2/7/132741508/mazepi.pdf
- http://files.wrprc.org/uploads/1/3/2/7/132740558/newufudulu.pdf
- http://files.paeoniapines.com/uploads/1/3/1/3/131380163/2483875.pdf
- https://uploads.strikinglycdn.com/files/89e0da90-0674-4cfe-9bfe-d206af7ddb86/52030245380.pdf
- https://uploads.strikinglycdn.com/files/518e2d6e-2675-40bd-92e7-361fa250ace3/lukaru.pdf
- https://uploads.strikinglycdn.com/files/4e1ddfe1-931d-4cd4-97a9-c35d8ec32c4b/2829254823.pdf
- https://uploads.strikinglycdn.com/files/88ada7ec-c6b4-46d0-96ad-73b3333bf911/difewafanosob.pdf
- http://worazivi.honoraryislander.com/uploads/1/3/2/6/132681361/9b25e.pdf
- http://files.mindfulmamayoga.com/uploads/1/3/1/3/131383456/9475299.pdf
- http://files.nomorescars.org/uploads/1/3/0/7/130776351/012490e60c8a.pdf
- http://files.michaelellisphotos.com/uploads/1/3/1/6/131636906/04d9ead5ec469e2.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787759921&P2=404&P3=2&P4=gfUa%2f%2f7Aw0LgYn5WOuHLv6Hk%2b4KbhhCAROFup2ItYx1xWCTsi9Bj3rt%2fyTdjgHGq2AyD80W%2bJx1wX2jqDMUY9A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Embedded domains
- gettraff.ru
- files.coffeynotes.com
- lojadurur.ryanlakanen.com
- files.wrprc.org
- files.paeoniapines.com
- uploads.strikinglycdn.com
- worazivi.honoraryislander.com
- files.mindfulmamayoga.com
- files.nomorescars.org
- files.michaelellisphotos.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 4.150.223.112
- 20.42.179.204
- 135.232.92.137
- 172.172.255.216
- 52.123.252.232
- 52.110.12.50
- 172.215.188.232
- 4.230.171.124
- 135.233.95.144
- 74.178.240.51
- 52.123.129.14
- 40.99.133.210
- 13.89.179.12
- 72.153.5.129
- 203.26.79.13
- 135.233.45.222
- 92.223.78.30
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report