SUSPICIOUS — lilivuwukatejibozorixaj.pdf
SUSPICIOUS — lilivuwukatejibozorixaj.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (64/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bd971976e6095584f8295776ceb2630832eee3fa2831f6b7127aac1bb2f66786 - SHA-1:
72299b857776c3d5d3c9840389b7c988248cf6f4 - MD5:
d49ab02c3a837f99e1fa9ba9f1526ba9 - ssdeep:
768:TgGzpDwpE1ZwpRbnVx+u/Y7Naf7SlMsbdMAPr7ediYXQSbGs+YfBJbWQAVoximgZ:sGFEpE6j/YAyS7+TQ5xiJMnZwAmp3J - TLSH:
T1CB33AFF354ABDD8C77826B53AC6A10657099C7CDB232DB6055CD762CC0AC3BE6E10A41 - Submitted as: lilivuwukatejibozorixaj.pdf
- File type: pdf · Size: 47685 bytes
- Verdict: suspicious (64/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 64/100 is the fusion of 5 weighted signals:
- Contacted 18 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=steins+gate+0+vn, https://cdn-cms.f-static.net/uploads/4366317/normal_5f872e1182c80.pdf, https://cdn-cms.f-static.net/uploads/4370263/normal_5f8814d7bb018.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (11 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9728 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787780867&P2=404&P3=2&P4=DjPH1uey3j%2bYpA7Fm6BV%2bWEtavPuwxGXUudN3%2btE48CQRMqcJZVeUyD5T7YxkFkWl9SAbYAFzlTho%2bQzDJOocg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787780936&P2=404&P3=2&P4=b8uQ%2b5tufMavdkeTFbE9CUDx%2bW5UflJ3jlKnbJd3TnN7pr56DuwwZzW751%2fReV23s8z83eNmX3BZGFKm45O71A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- 151.101.30.172
- 23.11.37.157
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
6838dedbbb9eda155509d9e224f32889cae15c72eb633a3d2cbb89dda674e82d - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\9c828661f5131129232589027ed9b01a.png -
00a2e2cbcf84ab2b656b317dbb7d05b03824e87006e3c933552162d2cd8b924c - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://gettraff.ru/strik?keyword=steins+gate+0+vn
- https://cdn-cms.f-static.net/uploads/4366317/normal_5f872e1182c80.pdf
- https://cdn-cms.f-static.net/uploads/4370263/normal_5f8814d7bb018.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f8817ef1cf2a.pdf
- https://cdn-cms.f-static.net/uploads/4367311/normal_5f87658754482.pdf
- https://cdn.shopify.com/s/files/1/0432/1624/0807/files/58931909088.pdf
- https://cdn.shopify.com/s/files/1/0497/3962/8703/files/butolivotusukipul.pdf
- https://cdn.shopify.com/s/files/1/0465/0552/5398/files/caesars_palace_parking.pdf
- https://cdn.shopify.com/s/files/1/0483/6638/7363/files/spirited_away_streaming_us.pdf
- https://cdn-cms.f-static.net/uploads/4366642/normal_5f87bb375322a.pdf
- https://cdn-cms.f-static.net/uploads/4366343/normal_5f87c90fa38fe.pdf
- https://cdn-cms.f-static.net/uploads/4367290/normal_5f886b4ac4320.pdf
- https://cdn-cms.f-static.net/uploads/4365580/normal_5f872c1ad9633.pdf
- https://cdn-cms.f-static.net/uploads/4374362/normal_5f8920d11dcfe.pdf
- https://cdn-cms.f-static.net/uploads/4367951/normal_5f88b61ad734b.pdf
- https://nagifinapu.weebly.com/uploads/1/3/2/6/132696111/7115017.pdf
- https://meboguvogo.weebly.com/uploads/1/3/1/4/131437667/lisibojuk.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/4041939.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- nagifinapu.weebly.com
- meboguvogo.weebly.com
- bedizegoresupa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 20.42.73.26
- 52.110.12.5
- 172.215.188.225
- 4.230.171.124
- 4.144.132.114
- 20.184.175.15
- 74.179.77.204
- 20.76.201.171
- 20.184.175.12
- 52.123.129.14
- 40.103.64.242
- 40.99.133.226
- 172.178.240.162
- 72.145.35.108
- 203.26.79.13
- 20.42.179.204
- 135.232.92.34
- 135.234.160.244
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report