MALICIOUS — 09273f_2576d2eba41641388313ebd7527ee23a.pdf
MALICIOUS — 09273f_2576d2eba41641388313ebd7527ee23a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6b10be7988a38fff3cd15fedfcdab6437e8566860df060399b4a28de0fe9656b - SHA-1:
30101b6e9322a90bda2244b549b11a416eb1d1ce - MD5:
63587c13881a13d9ed2aeb17676cc038 - ssdeep:
1536:TGFYTfAEzZjQfvxQ3M+suoABVRizTdWtKj:iFYTfAElkf4MjuoABDizTQty - TLSH:
T16A348DF364ABED8C79CA9F439DAA1059744AD789703396A056CC36BCC07C5BD2F00A21 - Submitted as: 09273f_2576d2eba41641388313ebd7527ee23a.pdf
- File type: pdf · Size: 52541 bytes
- Verdict: malicious (89/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 89/100 is the fusion of 8 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=ethnic+religion+meaning+in+hindi, https://48aaba2c-cc94-41d0-9f82-027d397ff1b6.filesusr.com/ugd/e3c460_4896ff8f03fd4ce984b941c78446251b.pdf?index=true, https://2efa6573-0b08-4293-851b-e9b909719b20.filesusr.com/ugd/2eedf1_6a9e033e86bc4f81b2a23a01b1b2a833.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 5 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1080 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 192.168.122.116
- 23.40.52.209
- 40.126.14.160
- 23.11.37.157
- 74.178.76.128 IE · Dublin · AS8075 Microsoft Corporation
- 20.190.142.164
- 104.18.33.89 US · San Francisco · AS13335 Cloudflare, Inc.
- 52.123.252.245 AU · Sydney · AS8075 Microsoft Corporation
- 23.221.133.223
- 23.33.238.189
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ttraff.ru/wix?keyword=ethnic+religion+meaning+in+hindi
- https://48aaba2c-cc94-41d0-9f82-027d397ff1b6.filesusr.com/ugd/e3c460_4896ff8f03fd4ce984b941c78446251b.pdf?index=true
- https://2efa6573-0b08-4293-851b-e9b909719b20.filesusr.com/ugd/2eedf1_6a9e033e86bc4f81b2a23a01b1b2a833.pdf?index=true
- https://56a7a614-79c8-433e-94aa-89e24697c6e3.filesusr.com/ugd/031dda_303d50de032b462b9924f833b1eb8c44.pdf?index=true
- https://0990a85d-fc44-454a-aa64-1687d2b149fd.filesusr.com/ugd/1b6cec_992526e17213414e8213b300cf9e527a.pdf?index=true
- https://f0ee4a34-2976-4c7e-9d3b-66efce4c1aba.filesusr.com/ugd/c1108c_caa74c6acf0345faa9c67ead6b2ff864.pdf?index=true
- https://cd10388b-8a0c-4e7b-8a4d-891d693c0695.filesusr.com/ugd/9bd82e_62ef9964fba14bd580dae011cc978381.pdf?index=true
- https://61785856-4600-4b4f-8652-e1a18426917d.filesusr.com/ugd/008a9f_093865c2e3b9469ca5cc6768e9c592e1.pdf?index=true
- https://6faf2e3e-31fc-4666-8287-9adddd6c4921.filesusr.com/ugd/843280_ab2b37f4bd6d4c288b70a76e86b13d1c.pdf?index=true
- http://tasozo.flowersindublin.com/uploads/1/3/1/4/131454215/xidujasawovab.pdf
- http://files.riverrunsighthounds.com/uploads/1/3/2/7/132741429/jujanisataf-jetikugivozexir-lobanajatemuku-tafodalaxowisow.pdf
- http://mopaxe.yogascapesinjapan.com/uploads/1/3/2/6/132696465/2ad5ede32.pdf
- http://gisimedi.aj-flower.com/uploads/1/3/2/3/132302720/fejifuwuva-nosobokikasevux-buxunim-wijiso.pdf
- http://nofuveviw.flippingcoinsgetaway.com/uploads/1/3/0/8/130874493/2044534.pdf
- https://ae4b2df4-ad72-4c0f-8e62-754a68a7f160.filesusr.com/ugd/221eaa_5918614d85d84fd1a02b6ad8b41b200a.pdf?index=true
- https://c4948f33-06e5-40f5-b8cc-a938ed4c4274.filesusr.com/ugd/a86d68_18d7e6d0371041f8bc163657a167ffec.pdf?index=true
- https://a2ee7701-0e0d-4c12-9c12-201ee6c5e08c.filesusr.com/ugd/b5aed9_1c5f54ae7bfe42b5bc69c6a9ec0feed1.pdf?index=true
- https://749e455f-6c97-48d7-8f7d-37030cdd4792.filesusr.com/ugd/2b25b5_7cc7549f940f4703971e4f729bd736e7.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- ttraff.ru
- 48aaba2c-cc94-41d0-9f82-027d397ff1b6.filesusr.com
- 2efa6573-0b08-4293-851b-e9b909719b20.filesusr.com
- 56a7a614-79c8-433e-94aa-89e24697c6e3.filesusr.com
- 0990a85d-fc44-454a-aa64-1687d2b149fd.filesusr.com
- f0ee4a34-2976-4c7e-9d3b-66efce4c1aba.filesusr.com
- cd10388b-8a0c-4e7b-8a4d-891d693c0695.filesusr.com
- 61785856-4600-4b4f-8652-e1a18426917d.filesusr.com
- 6faf2e3e-31fc-4666-8287-9adddd6c4921.filesusr.com
- tasozo.flowersindublin.com
- files.riverrunsighthounds.com
- mopaxe.yogascapesinjapan.com
- gisimedi.aj-flower.com
- nofuveviw.flippingcoinsgetaway.com
- ae4b2df4-ad72-4c0f-8e62-754a68a7f160.filesusr.com
- c4948f33-06e5-40f5-b8cc-a938ed4c4274.filesusr.com
- a2ee7701-0e0d-4c12-9c12-201ee6c5e08c.filesusr.com
- 749e455f-6c97-48d7-8f7d-37030cdd4792.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 74.178.76.128
- 104.18.33.89
- 52.123.252.245
- 51.132.193.108
- 162.159.36.2
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report