MALICIOUS — lotusutuke.pdf
MALICIOUS — lotusutuke.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
79bf95baccd55a47c149b2f1e7bb0af74ea8f093b15ae5837c19a6885f4654e0 - SHA-1:
33bce4c433dbca275247dd2ad9969797e10c9a2a - MD5:
2fb4dadc8df15ae1159b4b276a94e9fa - ssdeep:
768:zgGzpDiSeexxZjE/gYb7lqV3bjU5bGscMLrRx9rqQ/5y7kWxefHkp:MGFPeeEbAVsSMLrRx9rqQ/MkmefEp - TLSH:
T141338DF35193ED4C76CB9B536DBB119D608BD7882132D7A014887B2CD1BC6AE7E10A21 - Submitted as: lotusutuke.pdf
- File type: pdf · Size: 48353 bytes
- Verdict: malicious (86/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 86/100 is the fusion of 7 weighted signals:
- Memory forensics: 3 finding(s), e.g. RWX/private injected region in SumatraPDF.exe (pid 7512) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Contacted 26 external host(s) at runtime (23 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/5c64e7db-4e71-4256-90b6-8d5f1c6647d7/51981423400.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=convert+bitmap+image+into+pdf, https://site-1036742.mozfiles.com/files/1036742/jebunepuvobulitifopalen.pdf, https://site-1038830.mozfiles.com/files/1038830/89824073965.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (15 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
8684 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
7e2b233f25b2391967f734df3f26e9b09732b9e8bfe76ae96ef2451345b30f14 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\5ebec0ae225be22909a448137725eceb.png -
42f9640b6994e6cbbda2aee9712d2abd9bc41b3bd6d1a2b125223de399573cca
Embedded URLs
- https://ggtraff.ru/strik?keyword=convert+bitmap+image+into+pdf
- https://site-1036742.mozfiles.com/files/1036742/jebunepuvobulitifopalen.pdf
- https://site-1038830.mozfiles.com/files/1038830/89824073965.pdf
- https://site-1039435.mozfiles.com/files/1039435/16692259834.pdf
- https://site-1038827.mozfiles.com/files/1038827/wiralatot.pdf
- https://site-1043574.mozfiles.com/files/1043574/49150496370.pdf
- https://uploads.strikinglycdn.com/files/5c64e7db-4e71-4256-90b6-8d5f1c6647d7/51981423400.pdf
- https://uploads.strikinglycdn.com/files/f5f481d1-316a-4b84-a4db-bf42d259f955/45396931763.pdf
- https://uploads.strikinglycdn.com/files/8b8230fb-3a39-4f57-96a3-9c7569ba5e66/98119649923.pdf
- https://uploads.strikinglycdn.com/files/37b4ec41-0fcd-4c21-8d6e-4a115ec9a905/gezijig.pdf
- https://cdn-cms.f-static.net/uploads/4368227/normal_5f88b988319d0.pdf
- https://cdn-cms.f-static.net/uploads/4366973/normal_5f872c72098c5.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f87fb6cd62a7.pdf
- https://cdn-cms.f-static.net/uploads/4366407/normal_5f875d10a86ff.pdf
- https://cdn-cms.f-static.net/uploads/4367938/normal_5f87ebe86053e.pdf
- https://gusumadanu.weebly.com/uploads/1/3/2/6/132695601/6894496.pdf
- https://nesavelo.weebly.com/uploads/1/3/2/3/132303009/teporu-tixipavodupesu-lazibisawuz-buxezog.pdf
- https://tajurasexir.weebly.com/uploads/1/3/1/6/131606020/wonugoduludofasug.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/f9007.pdf
- https://zukamukenipebo.weebly.com/uploads/1/3/1/3/131380388/kedejunovozutezu.pdf
- https://uploads.strikinglycdn.com/files/1c83756f-b27e-4a95-bff4-5d1c04d28255/tabudapajotimina.pdf
- https://uploads.strikinglycdn.com/files/23fe212c-a017-4f0c-b9ab-cd7ad838e0dc/70100632638.pdf
- https://uploads.strikinglycdn.com/files/789d9f58-16a8-4330-a22b-87403cc6e7cc/68975314677.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- site-1036742.mozfiles.com
- site-1038830.mozfiles.com
- site-1039435.mozfiles.com
- site-1038827.mozfiles.com
- site-1043574.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- gusumadanu.weebly.com
- nesavelo.weebly.com
- tajurasexir.weebly.com
- dutitujazekap.weebly.com
- zukamukenipebo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.110.12.4
- 135.233.95.80
- 52.110.12.26
- 20.89.1.9
- 4.144.132.223
- 4.230.171.124
- 20.42.179.192
- 135.233.95.144
- 135.232.92.97
- 51.132.193.104
- 40.99.133.210
- 20.76.201.171
- 172.66.2.5
- 52.123.129.14
- 52.123.252.239
- 172.178.240.162
- 203.26.79.13
- 92.223.78.30
- 52.148.114.188
- 72.145.35.106
- 4.150.223.107
- 20.50.201.195
- 20.42.179.204
- 74.178.76.44
- 52.110.12.37
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report