MALICIOUS — megas_xlr_torrent.pdf
MALICIOUS — megas_xlr_torrent.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
ac76cf3f18f6e289dd098c93c918c474fa0e80cc1cedbc1bc84a4d489763ab1a - SHA-1:
3dd9cdf417b5e34d921e85d23a06f0fb8744bd0e - MD5:
aca7f4ec2be1b525a02940c83367b8c5 - ssdeep:
768:8gGzpD/pYyYWJ859dZEVhUDYgElyNFf//Y9TmypMTW2yWGiIeq:ZGFbppsg3lAfgCy+TWlaIeq - TLSH:
T122306CF75097ED8C7B8FAF039D9B219E6086C2896136D7A0088C772CC57CADD2E50A51 - Submitted as: megas_xlr_torrent.pdf
- File type: pdf · Size: 39266 bytes
- Verdict: malicious (72/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 72/100 is the fusion of 6 weighted signals:
- Contacted 16 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/5538c047-7a27-4958-937d-4548afd2cd80/15931394521.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=megas+xlr+torrent, https://tejigenunonim.weebly.com/uploads/1/3/0/8/130813632/xawapebuw.pdf, https://dosedupuwosiwoz.weebly.com/uploads/1/3/0/7/130776272/5614093.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (5 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9839 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 250.255.255.239.in-addr.arpa
- WORKGROUP
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
b6690a68d5886bf56a80ab5ecb241283f4d30023e8917932df3fd0fbea924ee2 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\6fcec9f1d832b931f02f22ef4728967e.png -
2a297ac4edd64b33f66e2a6ad0718f3cd6ab85c91914a1658948cf2eb5096491 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://gettraff.ru/strik?keyword=megas+xlr+torrent
- https://tejigenunonim.weebly.com/uploads/1/3/0/8/130813632/xawapebuw.pdf
- https://dosedupuwosiwoz.weebly.com/uploads/1/3/0/7/130776272/5614093.pdf
- https://narogigadi.weebly.com/uploads/1/3/0/8/130874066/5160106.pdf
- https://kilejotiwig.weebly.com/uploads/1/3/1/4/131406519/f1977.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/134863603f.pdf
- https://cdn.shopify.com/s/files/1/0484/9162/6657/files/massive_male_plus_reviews.pdf
- https://cdn.shopify.com/s/files/1/0437/0097/7829/files/south_dakota_medicaid_prior_authorization_phone_number.pdf
- https://cdn.shopify.com/s/files/1/0482/1788/2776/files/mavawajat.pdf
- https://cdn.shopify.com/s/files/1/0485/7207/2096/files/vojasosepepegara.pdf
- https://uploads.strikinglycdn.com/files/5538c047-7a27-4958-937d-4548afd2cd80/15931394521.pdf
- https://uploads.strikinglycdn.com/files/3997bc15-a6f6-4a3a-85f6-e0596d0faa18/35990113036.pdf
- https://uploads.strikinglycdn.com/files/c04f4d70-8cfa-45a7-b09a-ea68ac7f1c87/loxijufanevesug.pdf
- https://uploads.strikinglycdn.com/files/574c60e7-17c6-4dd2-951b-7fc29ea3b834/difiwaligikenof.pdf
- https://buveziketi.weebly.com/uploads/1/3/1/3/131398526/jefasazefuso_zazebaxusev_nubilikose_zeluribagazuwo.pdf
- https://buveziketi.weebly.com/uploads/1/3/1/3/131398526/jotepibumobudino.pdf
- https://relogeseji.weebly.com/uploads/1/3/0/7/130739887/7247227.pdf
- https://sokuvotaboraj.weebly.com/uploads/1/3/0/7/130776263/52a3c1c11a8a7.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/selagu-wugixinoxule.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/belapigojat.pdf
- https://pimetagedipimop.weebly.com/uploads/1/3/1/6/131636886/8f7ca19905ed.pdf
- https://vonubaxuted.weebly.com/uploads/1/3/1/4/131452839/gegudas-vepizusek-lozenurabiwepaj.pdf
- https://cdn-cms.f-static.net/uploads/4368485/normal_5f8b13fed7e05.pdf
- https://cdn-cms.f-static.net/uploads/4366047/normal_5f880f8c47a21.pdf
- https://cdn-cms.f-static.net/uploads/4366653/normal_5f8ba31537256.pdf
Embedded domains
- gettraff.ru
- tejigenunonim.weebly.com
- dosedupuwosiwoz.weebly.com
- narogigadi.weebly.com
- kilejotiwig.weebly.com
- juragubiv.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- buveziketi.weebly.com
- relogeseji.weebly.com
- sokuvotaboraj.weebly.com
- boguvetasitob.weebly.com
- guwomenod.weebly.com
- pimetagedipimop.weebly.com
- vonubaxuted.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 172.172.255.217
- 74.178.76.128
- 162.159.142.9
- 51.105.71.136
- 52.110.12.50
- 4.230.171.124
- 57.155.101.212
- 40.79.167.9
- 20.112.250.133
- 52.123.128.14
- 135.234.160.246
- 74.178.232.29
- 203.26.79.13
- 172.178.240.163
- 52.148.114.188
- 142.250.195.163
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report