SUSPICIOUS — vizutubo.pdf
SUSPICIOUS — vizutubo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (56/100). 2 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
94b7cbf3e8d767c7e099c417f3ac90229b77e258cfb9fbd96085aef1ac01eafb - SHA-1:
315dc189e8cbb9f1cb180e2e24830354b4b7cd09 - MD5:
9927ec832f21d37f89f7f8612f4f2d7f - ssdeep:
768:tgGzpDNp1QfsIF/a4ccE006/U8X0PiNrUXIiH7YK//i:OGFpp+ti4cdH6/UPiNfi0K//i - TLSH:
T12032AFF35157DC4D798BAB43AEF5244EA08AC6883173E39008DC772DC9B85AC6F006A1 - Submitted as: vizutubo.pdf
- File type: pdf · Size: 43308 bytes
- Verdict: suspicious (56/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 56/100 is the fusion of 6 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=wedding+dash+deluxe+free+full+versio, https://uploads.strikinglycdn.com/files/68ca7a45-e21c-495c-9066-4e220549b8ed/xuzufitovaxoluge.pdf, https://uploads.strikinglycdn.com/files/d527d965-efaa-4771-9d42-4e9c1724bbbf/86334866857.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 6 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (11 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9713 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- searchapp.bundleassets.example
- inference.location.live.net
- staging.to-do.officeppe.com
- desktop-hsgcbep
- 255.255.254.169.in-addr.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 251.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- 79.243.254.169.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- 23.40.52.209
- 172.66.2.5 US · San Francisco · AS13335 Cloudflare, Inc.
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
c9488e7672d605448fc46888f0f9b42d8089821d8e463420ce446cefc1384573 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\71a3676abea9e1c8fc3d16efc4d2f4cb.png -
433e695b0e2414ece2ab0efe545f98c151bb47a76c952b1824dd754db0f3fe7a - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://cctraff.ru/strik?keyword=wedding+dash+deluxe+free+full+versio
- https://uploads.strikinglycdn.com/files/68ca7a45-e21c-495c-9066-4e220549b8ed/xuzufitovaxoluge.pdf
- https://uploads.strikinglycdn.com/files/d527d965-efaa-4771-9d42-4e9c1724bbbf/86334866857.pdf
- https://uploads.strikinglycdn.com/files/c143c5d1-933c-4648-a604-b599bb2dfb45/fixosotexopitonote.pdf
- https://uploads.strikinglycdn.com/files/c2cc162b-6826-40fc-81b5-538eefcc4373/lupizosu.pdf
- https://site-1036678.mozfiles.com/files/1036678/65871557486.pdf
- https://site-1038581.mozfiles.com/files/1038581/65012665712.pdf
- https://uploads.strikinglycdn.com/files/bf37581d-2b91-465e-bde5-7a149a458b17/dekubizinupeg.pdf
- https://uploads.strikinglycdn.com/files/8a7ca191-1922-400c-b801-e9ca0facab0f/3902153965.pdf
- https://uploads.strikinglycdn.com/files/458fb07f-6240-45e6-8ccd-d377b5135d8b/tokizorusufiwid.pdf
- https://uploads.strikinglycdn.com/files/ccee862d-14c8-4751-bc5c-a7aec64f5d0d/kulurose.pdf
- https://cdn.shopify.com/s/files/1/0432/3262/4797/files/lg_xl44_oven_manual.pdf
- https://cdn.shopify.com/s/files/1/0486/0208/7584/files/xedojagejilatomo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1036678.mozfiles.com
- site-1038581.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 4.150.223.99
- 172.66.2.5
- 74.179.71.159
- 135.233.95.144
- 162.159.36.2
- 4.230.171.124
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report