MALICIOUS — pure_competition_definition_in_finance.pdf
MALICIOUS — pure_competition_definition_in_finance.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
750d558410eaeb874097b5325ca02c30e1188b580c181af73f9e499e982fa5c8 - SHA-1:
96ae127f50e63d35f6033a4edd6a2e2e726d156e - MD5:
f8cb18c3185118afd98a13a4b2ec6179 - ssdeep:
1536:CGFcY/nOiUPSUz9q6s4PI30m1vvrwcqkmOvMMC86zZ:7FcanOj9q6sNkm5ctpO0Z8s - TLSH:
T15E38D0F300A7ED4E798BAB83AABA314D544BC38E5136E7600588B76CD1BC5DD7E10852 - Submitted as: pure_competition_definition_in_finance.pdf
- File type: pdf · Size: 78999 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 7 weighted signals:
- Contacted 11 external host(s) at runtime (2 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/52b785a9-826d-49e2-b511-b7fc1882174a/fariwevutiku.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=pure+competition+definition+in+finance, https://cdn.shopify.com/s/files/1/0501/5837/1009/files/perudumifaj.pdf, https://uploads.strikinglycdn.com/files/986e5729-0272-4b7a-a43e-efeddc508139/wosakozir.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9618 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\336b627e1cfa6c0cc8f95ac31d8b2d1e.png -
b7d4bb0cff089fa59eb006dce51281452d3e34bedfd91bfe5e068239c4fc5c4b - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
295dd4839f03ce56d7297ab9bcd91b73147f04c7de4300309a145f2edfdbaf75 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://gettraff.ru/strik?keyword=pure+competition+definition+in+finance
- https://cdn.shopify.com/s/files/1/0501/5837/1009/files/perudumifaj.pdf
- https://uploads.strikinglycdn.com/files/986e5729-0272-4b7a-a43e-efeddc508139/wosakozir.pdf
- https://uploads.strikinglycdn.com/files/e3d873cd-04d0-472b-98d9-c6ebbcdb0e70/bumuvinijit.pdf
- https://cdn.shopify.com/s/files/1/0435/4362/5880/files/tiffin_movie_theater_bed_bugs.pdf
- https://uploads.strikinglycdn.com/files/52b785a9-826d-49e2-b511-b7fc1882174a/fariwevutiku.pdf
- https://cdn.shopify.com/s/files/1/0478/4173/8911/files/43043332299.pdf
- https://cdn.shopify.com/s/files/1/0434/0314/9479/files/97772786451.pdf
- https://cdn.shopify.com/s/files/1/0499/3826/8318/files/dent_mod_apk_unlimited_money.pdf
- https://zadumeredevasax.weebly.com/uploads/1/3/1/4/131453870/411cd83.pdf
- https://cdn.shopify.com/s/files/1/0504/9624/1856/files/88235452077.pdf
- https://jutawalafomas.weebly.com/uploads/1/3/4/3/134316275/zitanetuvov.pdf
- https://cdn.shopify.com/s/files/1/0501/2986/2816/files/corpse_party_manga_order.pdf
- https://cdn.shopify.com/s/files/1/0432/3357/5075/files/28927161098.pdf
- https://cdn.shopify.com/s/files/1/0486/4848/7070/files/67093640169.pdf
- https://cdn.shopify.com/s/files/1/0485/2465/6802/files/the_prince__me_2_the_royal_wedding.pdf
- https://uploads.strikinglycdn.com/files/4aceed9b-df5c-4f8e-a530-9742356d954e/418222429.pdf
- https://uploads.strikinglycdn.com/files/6e6a1167-d8fb-4099-9bee-17bddb6cd985/partes_de_un_ensayo.pdf
- https://uploads.strikinglycdn.com/files/27ad40f2-ba36-4872-bbac-0d91cbe25e94/41979053224.pdf
- https://cdn.shopify.com/s/files/1/0481/4415/4791/files/32612247391.pdf
- https://uploads.strikinglycdn.com/files/4ba52731-b380-4333-8b0c-bb9b9a36e69b/53769341847.pdf
- https://uploads.strikinglycdn.com/files/e92bc729-e201-4b7e-82b5-9522b6671e1b/vanenozaki.pdf
- https://uploads.strikinglycdn.com/files/4373da29-f2fb-4db5-9e6a-b418815db804/dofitigijufadorurubokoki.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- zadumeredevasax.weebly.com
- jutawalafomas.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.178.17.235
- 57.154.63.210
- 52.110.12.18
- 4.230.171.124
- 74.178.76.128
- 135.232.92.97
- 52.123.128.14
- 52.123.252.230
- 74.178.76.44
- 72.145.35.110
- 203.26.79.13
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report