MALICIOUS — a37a2e_584aacb8d2514e2ab5e370354084a155.pdf
MALICIOUS — a37a2e_584aacb8d2514e2ab5e370354084a155.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
62b3fda99ba6d14a0abb7d4c79db037d6a3feb27e1b6017a369bc4fed0639a36 - SHA-1:
35a049051346ca605d232d7aae2ad7d091ec4d9e - MD5:
27c1cfcd99b74ed699ff1b176858393d - ssdeep:
768:TgGzpD6AIfsWp218xPKc/nw9phgNohsgNShC37ryGtTwPv3cFadlZ:sGFmAIJ218XvSphgNoaAuC3ZksFadlZ - TLSH:
T1FB329EF3109BEC8C7B8F5F43AEAA249D50C5D28D6023926454AC772CC47C7ED6E61A21 - Submitted as: a37a2e_584aacb8d2514e2ab5e370354084a155.pdf
- File type: pdf · Size: 47124 bytes
- Verdict: malicious (89/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 89/100 is the fusion of 8 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.PDF.Agent.gen (rule
HEUR:Trojan.PDF.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.cc/wix?keyword=x+laser+skywriter+hpx+manual, http://gofusa.66-marketplace.com/uploads/1/3/1/4/131453603/lavijabuzegu.pdf, http://files.massimomonacelli.com/uploads/1/3/2/7/132712451/4dca9.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 11 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (17 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
989 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- searchapp.bundleassets.example
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- to-do.office.com
- staging.to-do.officeppe.com
- m365.cloud.microsoft
- res.public.onecdn.static.microsoft
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
- 150.171.22.17
- 52.110.12.15 AU · Sydney · AS8075 Microsoft Corporation
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ttraff.cc/wix?keyword=x+laser+skywriter+hpx+manual
- http://gofusa.66-marketplace.com/uploads/1/3/1/4/131453603/lavijabuzegu.pdf
- http://files.massimomonacelli.com/uploads/1/3/2/7/132712451/4dca9.pdf
- http://files.f-y-t-a.com/uploads/1/3/1/3/131380107/vurimemotosatewedosa.pdf
- http://files.govipgolfcarts.com/uploads/1/3/1/4/131407388/givutujak.pdf
- http://zujokel.theplastereddragon.com/uploads/1/3/1/6/131606617/josod.pdf
- https://be4028e5-af5c-499d-a9de-0d063955ecec.filesusr.com/ugd/911c12_dd5339112ee4424089fa7c7f545e88c5.pdf?index=true
- https://24d63bbf-61e0-478a-8606-7dab265acaab.filesusr.com/ugd/12daa7_a30ab62f6ffb4a5494c72a886fb790d4.pdf?index=true
- https://bba9c1bd-5da6-4d35-bc76-93b5fb954af8.filesusr.com/ugd/7a7fb1_237d69f8a6104cf999d413bf56f37a21.pdf?index=true
- http://files.bodytherapybydai.com/uploads/1/3/1/3/131398573/21a80.pdf
- http://files.teachermomlifeblog.com/uploads/1/3/2/6/132681477/kapudunerolev.pdf
- http://xitelasef.bibletourlouvre.com/uploads/1/3/1/1/131163729/730be074a52506b.pdf
- https://b40936a7-ebf2-4b82-960d-a84609ac27b7.filesusr.com/ugd/6cfc61_e1189696647849c3912e3e8507b90dd8.pdf?index=true
- https://ad01d503-cbba-4465-9a32-4911b8a9dfdd.filesusr.com/ugd/f46427_573a69bc27a742f99936a3ca4bc2dbf8.pdf?index=true
- https://bb0b68dc-05be-4a75-bc8f-989d7a20b74c.filesusr.com/ugd/b6bf5b_c9de9c6c444640feb130263947eca68d.pdf?index=true
- https://9334bc97-9bfd-4f25-bb76-763793c5a5c6.filesusr.com/ugd/cdfdba_6becf765f8f24a99819a6a49c9c80adb.pdf?index=true
- https://fc917533-7dc0-49f2-b0e5-04c649359f92.filesusr.com/ugd/4b874d_5cccf342e73743b6bb5c7e20c6341da2.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcb.com/rb.crl
Embedded domains
- ttraff.cc
- gofusa.66-marketplace.com
- files.massimomonacelli.com
- files.f-y-t-a.com
- files.govipgolfcarts.com
- zujokel.theplastereddragon.com
- be4028e5-af5c-499d-a9de-0d063955ecec.filesusr.com
- 24d63bbf-61e0-478a-8606-7dab265acaab.filesusr.com
- bba9c1bd-5da6-4d35-bc76-93b5fb954af8.filesusr.com
- files.bodytherapybydai.com
- files.teachermomlifeblog.com
- xitelasef.bibletourlouvre.com
- b40936a7-ebf2-4b82-960d-a84609ac27b7.filesusr.com
- ad01d503-cbba-4465-9a32-4911b8a9dfdd.filesusr.com
- bb0b68dc-05be-4a75-bc8f-989d7a20b74c.filesusr.com
- 9334bc97-9bfd-4f25-bb76-763793c5a5c6.filesusr.com
- fc917533-7dc0-49f2-b0e5-04c649359f92.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
- res.public.onecdn.static.microsoft
Embedded IP addresses
- 52.110.12.15
- 74.179.77.204
- 40.104.4.2
- 40.103.64.226
- 104.18.19.203
- 52.123.252.235
- 20.184.175.11
- 52.123.252.243
- 4.230.171.124
- 203.26.79.13
- 104.18.18.203
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report