SUSPICIOUS — xivugezalogaro.pdf
SUSPICIOUS — xivugezalogaro.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (68/100). 2 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
94a0ece9a53c02e1564c4c7ad4f42a82aff7f874e79d7ceca75634c3c0fe9d25 - SHA-1:
c156037d008546f1cec2a21b04f4adcf3a6d0c1c - MD5:
cd25ace2df57bf74be199e8964b0c426 - ssdeep:
768:5gGzpDIe5whHGo4Vw88yg7jms9G7fvyK8ZPPu6Ho1wOAUWA7rEj+CKdy+4IB:6GFEe1sGLuRuAfOAgEj+CKB4IB - TLSH:
T178326CF3109BEE8D7A8B9B43ADBA159A218AD74C71339750448C772DC47C2AD7F10990 - Submitted as: xivugezalogaro.pdf
- File type: pdf · Size: 44651 bytes
- Verdict: suspicious (68/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 68/100 is the fusion of 6 weighted signals:
- Contacted 18 external host(s) at runtime (2 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=exercice%20ce2%20s%20ou%20ss, https://cdn-cms.f-static.net/uploads/4365619/normal_5f883ea664ba6.pdf, https://cdn-cms.f-static.net/uploads/4370561/normal_5f8a3f11688ac.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9893 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- desktop-hsgcbep(1)._dosvc._tcp.local
- _dosvc._tcp.local
- 250.255.255.239.in-addr.arpa
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\592f3ca6ab85f98f26e2ba8b982a4d58.png -
d76607ab5625c8462eb023dde68df89eaadb6bc2307f61d29896f7d538b103a4 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
6bc99be73356dbc226f59a00e7944dd43340b5c5888b2257532f935c98b3fbe2 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://cctraff.ru/wb?keyword=exercice%20ce2%20s%20ou%20ss
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f883ea664ba6.pdf
- https://cdn-cms.f-static.net/uploads/4370561/normal_5f8a3f11688ac.pdf
- https://cdn-cms.f-static.net/uploads/4367019/normal_5f88548191a8c.pdf
- https://cdn-cms.f-static.net/uploads/4373004/normal_5f893c7803438.pdf
- https://cdn.shopify.com/s/files/1/0439/7583/5806/files/funcion_raiz_cuadrada_definicion.pdf
- https://cdn.shopify.com/s/files/1/0435/1816/5146/files/snapper_weed_eater_manual.pdf
- https://uploads.strikinglycdn.com/files/e03950bd-fce5-4fb4-870d-cb075a61eaf9/tixosomalubasaw.pdf
- https://uploads.strikinglycdn.com/files/7bda5a1f-8965-40ab-a3ca-755391c597bb/newarabi.pdf
- https://uploads.strikinglycdn.com/files/315e1540-bfd0-40e5-b2d2-61b5fcdc8ac3/2365024523.pdf
- https://uploads.strikinglycdn.com/files/6ae8b7c6-6a00-4058-b034-f0a652352849/tigewaxed.pdf
- https://uploads.strikinglycdn.com/files/a50aa1f9-b9b0-47e5-bb64-4d62d27d8546/79465845546.pdf
- https://uploads.strikinglycdn.com/files/2eab3976-937c-4d9d-99c2-76997922ce32/lojovakuwinelunemabi.pdf
- https://uploads.strikinglycdn.com/files/36dc75ef-758e-44bf-b4c1-939fc2197f52/jipuvirixebavel.pdf
- https://uploads.strikinglycdn.com/files/b3b3e46b-2d92-4e7c-a05a-99b6b00236e8/85147658747.pdf
- https://uploads.strikinglycdn.com/files/f30f9a94-430d-4afd-a800-f88469b80c54/jerijirunobogozojijupezi.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/837046.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/6443274.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/6023986.pdf
- https://virataxutepubom.weebly.com/uploads/1/3/0/8/130874282/kimodusanadumom.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/nukunuraki.pdf
- https://cdn.shopify.com/s/files/1/0482/4816/0411/files/jijedeguweluv.pdf
- https://cdn.shopify.com/s/files/1/0499/9738/1782/files/dutch_lap_vinyl_siding_dimensions.pdf
- https://cdn.shopify.com/s/files/1/0435/2845/4298/files/80562024941.pdf
- https://cdn.shopify.com/s/files/1/0501/8628/9333/files/69876831803.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- bedizegoresupa.weebly.com
- sesuwulot.weebly.com
- genigudepa.weebly.com
- virataxutepubom.weebly.com
- guwomenod.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 4.150.223.112
- 172.66.2.5
- 20.184.175.6
- 52.123.252.198
- 4.144.132.114
- 52.110.12.37
- 172.215.188.225
- 4.230.171.124
- 4.150.223.114
- 20.76.201.171
- 52.123.252.231
- 74.178.240.61
- 74.178.232.29
- 162.159.142.9
- 52.123.128.14
- 92.223.78.30
- 72.145.35.106
- 203.26.79.13
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report