SUSPICIOUS — kujom.pdf
SUSPICIOUS — kujom.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (66/100). 3 of 53 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
66cd9e1770e12be6a6ae593f9bb1a8f2f67b24a692915f9e915d9b0ac38e7b3b - SHA-1:
a303c1768cb8c08c8b8ba4aaef38bfab23054659 - MD5:
2e68f09aa6082a16855698367a37c6d3 - ssdeep:
768:xgGzpDwoF69d27252n+Qo/4cjovCBgMG2A4D52KCsX8ZgJWEolbW0yJ:CGFkoxI62x52KCOigJWbbW0yJ - TLSH:
T16E317DF310A7DC8C3A8BAF076DB6159D148EC7896136E7A0448C7B6C84BC6AD3F01861 - Submitted as: kujom.pdf
- File type: pdf · Size: 41038 bytes
- Verdict: suspicious (66/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 66/100 is the fusion of 7 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/248e8648-186a-4c40-be52-b0ebf3e46d64/49006183089.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=dawn+redwood+bonsai+for+sale, https://uploads.strikinglycdn.com/files/78c3214e-7aea-4318-bd61-fa746fb439af/23489294062.pdf, https://uploads.strikinglycdn.com/files/cea23383-80d0-45d7-9883-3e000db8c838/kanalis.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 10 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (12 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
10146 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- ntp.ubuntu.com
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep._dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\de2d459dba95c39e535c07c6d9668f8b.png -
7463fb64bb5b7453ce027889b7737ab630836d12cdb3c1414edc41af90c87efe - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
b57790b60951e902783621c3e5c394fb533048df886ffa01b769d155d187f875 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://cctraff.ru/strik?keyword=dawn+redwood+bonsai+for+sale
- https://uploads.strikinglycdn.com/files/78c3214e-7aea-4318-bd61-fa746fb439af/23489294062.pdf
- https://s3.amazonaws.com/laradusa/mountain_river_handicraft_incense_holder.pdf
- https://uploads.strikinglycdn.com/files/cea23383-80d0-45d7-9883-3e000db8c838/kanalis.pdf
- https://uploads.strikinglycdn.com/files/248e8648-186a-4c40-be52-b0ebf3e46d64/49006183089.pdf
- https://s3.amazonaws.com/kudufigunabi/remove_bookmarks_from_online_free.pdf
- https://cdn-cms.f-static.net/uploads/4366964/normal_5f8744966e805.pdf
- https://s3.amazonaws.com/henghuili-files2/ncert_physics_book_download_in_hindi.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f870110a5004.pdf
- https://uploads.strikinglycdn.com/files/872671ac-d0ee-4d66-94b1-213c49ca0eae/visotofajutulamasu.pdf
- https://s3.amazonaws.com/robumuduluwise/luxuw.pdf
- https://s3.amazonaws.com/sefukirexuwekij/wanovidaponisopogifuba.pdf
- https://s3.amazonaws.com/lebaxa/bovopiremiditig.pdf
- https://s3.amazonaws.com/jeworurowam/fender_rolling_near_me.pdf
- https://uploads.strikinglycdn.com/files/629a8287-ca0e-427d-9226-76e3ab812a14/javakesivisurogegepog.pdf
- https://uploads.strikinglycdn.com/files/476f2cb6-31ee-4c08-bec5-d5c24a519639/de_noche_y_dia_enrique_iglesias_mp3.pdf
- https://s3.amazonaws.com/solonebosop/catalytic_cracking_of_petroleum.pdf
- https://uploads.strikinglycdn.com/files/2c919f66-3f2e-48d1-8c8b-83f4a6897a35/93006685983.pdf
- https://uploads.strikinglycdn.com/files/056e31d3-7aec-495a-b9e9-37b7610959e9/16857646948.pdf
- https://cdn-cms.f-static.net/uploads/4388629/normal_5f8d8ae29d690.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f874f6036ecb.pdf
- https://uploads.strikinglycdn.com/files/a527671c-0310-4a77-acd5-c600277a9b03/gaduf.pdf
- https://cdn-cms.f-static.net/uploads/4379855/normal_5f919f82b1ee8.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 20.42.65.89
- 20.236.44.162
- 4.230.171.124
- 52.110.12.32
- 20.165.94.63
- 52.253.84.76
- 135.232.92.34
- 52.123.129.14
- 40.84.97.4
- 20.112.250.133
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report