SUSPICIOUS — xufoxafukawofe.pdf
SUSPICIOUS — xufoxafukawofe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (64/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
80cfed259b0d30b6649e7d99dc2ed26323f2cbdeee1771312199e35596cb214e - SHA-1:
6665d84588a2a3f15efc8b6393de219f17989edd - MD5:
23328cb800d61b8bfb013ec5efb3acf9 - ssdeep:
1536:3GF7mjWlmRrds2Hna0M0+AtSb9zp2yNMluQYc5fvb9npDs+JeLQ3cYu:WF7hlmRrO2Hvp+GglUV35fvb3DWLY+ - TLSH:
T14E3BE1F7201AED4CAB8337476DFA106D6285D388A037A55110847A7DD9AC7BDBF81A30 - Submitted as: xufoxafukawofe.pdf
- File type: pdf · Size: 103654 bytes
- Verdict: suspicious (64/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 64/100 is the fusion of 5 weighted signals:
- Contacted 13 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=automatic+teller+machine+pdf, https://site-1036965.mozfiles.com/files/1036965/60746458604.pdf, https://site-1036772.mozfiles.com/files/1036772/65396828995.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (15 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9809 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787773703&P2=404&P3=2&P4=a1nQvxJPQ6ZzBj7oykgxXmv6VlHYgjj0RMp0ATtQ2SGNDwPo%2b9ibUCL3kX6RL4GD1pFA6z%2ftHIrafDxr9M89Fg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787773790&P2=404&P3=2&P4=C%2fanoiHPTvSR4O99AvmqEbquciA6vHIWIFsIR55cml27FHyCz7NA9L5msyuiPv3tUjYAfAYrLvzPFcYNyNgPqQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- 23.40.52.85
- 23.11.37.157
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
10706b10ce812a919ac585242fbd133f14dea8963b8ec16517fc69bf7c6aa9dd - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\96446bb25365cc3d68f816f7d3bfbbbb.png -
42f19007477c1fd13ec516e0fca8fdb90860933bcf179ee7b5095ed67e1eeca0 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ggtraff.ru/strik?keyword=automatic+teller+machine+pdf
- https://site-1036965.mozfiles.com/files/1036965/60746458604.pdf
- https://site-1036772.mozfiles.com/files/1036772/65396828995.pdf
- https://site-1036711.mozfiles.com/files/1036711/75994722774.pdf
- https://site-1037079.mozfiles.com/files/1037079/24910119624.pdf
- https://site-1037187.mozfiles.com/files/1037187/87709160086.pdf
- http://files.lauramassimini.com/uploads/1/3/2/8/132814168/4cc1ffc5d994dca.pdf
- http://medazuni.outnorth.org/uploads/1/3/2/3/132303079/vogepasudelal_lexiluruvame.pdf
- http://rugodo.thecareconnector.com/uploads/1/3/2/6/132681293/9599f8ed568c18b.pdf
- http://files.exeteruniversitykarate.co.uk/uploads/1/3/1/3/131398260/sebozuvov.pdf
- http://nupagu.reviewgraphs.com/uploads/1/3/1/6/131636825/jizamitolozit.pdf
- http://files.mtzionucc.org/uploads/1/3/0/9/130969036/5e1f9a7.pdf
- https://site-1037055.mozfiles.com/files/1037055/xarem.pdf
- https://site-1036898.mozfiles.com/files/1036898/podeka.pdf
- https://site-1037230.mozfiles.com/files/1037230/pakatobup.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Embedded domains
- ggtraff.ru
- site-1036965.mozfiles.com
- site-1036772.mozfiles.com
- site-1036711.mozfiles.com
- site-1037079.mozfiles.com
- site-1037187.mozfiles.com
- files.lauramassimini.com
- medazuni.outnorth.org
- rugodo.thecareconnector.com
- files.exeteruniversitykarate.co.uk
- nupagu.reviewgraphs.com
- files.mtzionucc.org
- site-1037055.mozfiles.com
- site-1036898.mozfiles.com
- site-1037230.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 20.42.65.90
- 4.144.132.114
- 52.110.12.14
- 4.230.171.124
- 4.150.223.112
- 74.179.77.204
- 52.123.128.14
- 40.103.64.242
- 52.123.252.244
- 72.154.7.102
- 203.26.79.13
- 4.207.44.76
- 135.233.95.80
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report