MALICIOUS — 76056489811.pdf
MALICIOUS — 76056489811.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
73bab93d382706985c19d95fbaaaa003b356b069e60135f80d295ef111f93d08 - SHA-1:
d37d3822c0d56abb73586101196262113bff8d3a - MD5:
077c9e776239862dd4f905259ccf9c4d - ssdeep:
768:JgGzpD7wJtbZJagMxegWQqO/YANtHIH3NuHxTc:qGFHWt9IgMUgRYopIHIHxTc - TLSH:
T192329DF751B7EC8C31869B036EEA295D414AC78C6122A6A056CC777CC4BC37EBE50A50 - Submitted as: 76056489811.pdf
- File type: pdf · Size: 43994 bytes
- Verdict: malicious (72/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 72/100 is the fusion of 6 weighted signals:
- Contacted 19 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/322b3e40-1562-452d-b4f5-baa666e35bdf/95961806564.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=wastewater+treatment+in+beverage+industry+pdf, https://uploads.strikinglycdn.com/files/322b3e40-1562-452d-b4f5-baa666e35bdf/95961806564.pdf, https://uploads.strikinglycdn.com/files/d7c2278e-5ea3-4d8a-bd1c-274ebb69202b/34238245328.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (17 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9891 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- 255.255.254.169.in-addr.arpa
- 251.0.0.224.in-addr.arpa
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
e7946a2a76ceb72a0c399aa58ef9837dfd30d1cd56e3ab78df9c8abdd2365f85 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\3cb4da489b29657351889782097e0f53.png -
859441c6e61385a0c0e41e51eafb3f0376a67e64a10995d7cda872c90cb55b45 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://gettraff.ru/strik?keyword=wastewater+treatment+in+beverage+industry+pdf
- https://uploads.strikinglycdn.com/files/322b3e40-1562-452d-b4f5-baa666e35bdf/95961806564.pdf
- https://uploads.strikinglycdn.com/files/d7c2278e-5ea3-4d8a-bd1c-274ebb69202b/34238245328.pdf
- https://uploads.strikinglycdn.com/files/cefe10d6-4d51-4404-a177-e0fc21e48972/bibaketorenofo.pdf
- https://uploads.strikinglycdn.com/files/e15073c1-6693-4538-ab69-2d4b0e4e4e70/tomotamemorufirupedokon.pdf
- https://uploads.strikinglycdn.com/files/42a52693-7ad2-4b1b-9f6b-0c8391bc53a9/97665257231.pdf
- https://uploads.strikinglycdn.com/files/8ddc111f-1eee-4ace-9f15-a846c1a10356/30347008175.pdf
- https://uploads.strikinglycdn.com/files/25bb4896-3bc3-4ae7-ae1a-c51776dea146/89231635249.pdf
- https://uploads.strikinglycdn.com/files/9a9a2754-4c0f-4717-b5b4-f9668ebc64d5/3087202549.pdf
- https://uploads.strikinglycdn.com/files/0a1d6186-5ef5-4203-8296-49f530dccd9d/narepabijepig.pdf
- https://uploads.strikinglycdn.com/files/530f03a6-f4e6-4842-b3a6-3c7c5900d30e/nudakerorupomoku.pdf
- https://uploads.strikinglycdn.com/files/988d6c9a-2fc7-4ea7-9257-b3157e8ae030/64164541551.pdf
- https://uploads.strikinglycdn.com/files/48c312fa-a40a-4acd-ad76-cc44e2b79c5a/gesubevalidovu.pdf
- http://files.porterfinancescam.greatwebsitebuilder.com/uploads/1/3/1/1/131164520/4956212.pdf
- http://seluzo.genawave.com/uploads/1/3/1/3/131398177/detanu_kavawape_zopenuri.pdf
- http://golosu.serendipityacappella.net/uploads/1/3/0/7/130776228/xijuxem_xirosajumev_toxawe.pdf
- http://fenigem.phonecharmed.com/uploads/1/3/1/3/131398504/23185.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- files.porterfinancescam.greatwebsitebuilder.com
- seluzo.genawave.com
- golosu.serendipityacappella.net
- fenigem.phonecharmed.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.123.128.14
- 135.233.95.144
- 162.159.142.9
- 40.79.163.155
- 52.230.60.54
- 20.42.179.192
- 4.230.171.124
- 74.179.77.204
- 20.184.175.19
- 20.52.64.200
- 52.123.129.14
- 135.232.92.34
- 203.26.79.13
- 135.234.160.244
- 92.223.78.30
- 135.233.45.223
- 48.199.12.1
- 52.148.114.188
- 142.250.183.35
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report