MALICIOUS — fupofovujufuxuto.pdf
MALICIOUS — fupofovujufuxuto.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (80/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c37e39ec8f35f78b2eb9c39c8a07776448b721f6c7d348afad5206ada1678766 - SHA-1:
8f17e6b8c291115d6f107eacb730a52351ce7e7c - MD5:
de091676883ecb781c6dc11ddea6629e - ssdeep:
768:IgGzpDr+X+1gRmO5dLSA6MoaftLqwqJvhOP4BNA9Jm0KjVPn2ZzZz7F:FGFXcUggUmzMP5KhpbA9U0KhPn2ZNz7F - TLSH:
T12D319FB346D7ED487A86A70369B534582947D9DE102393B4A8AC373CC8BC5BD7F60860 - Submitted as: fupofovujufuxuto.pdf
- File type: pdf · Size: 41389 bytes
- Verdict: malicious (80/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 80/100 is the fusion of 7 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://cctraff.ru/strik?keyword=caterpillar+c32+generator+manual+pdf, https://site-1036685.mozfiles.com/files/1036685/zunewuvegew.pdf, https://site-1037224.mozfiles.com/files/1037224/dotomuwedarisufamilebuzal.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 8 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (12 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1031 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- teams.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- 192.168.122.115
- 23.40.52.209
- 23.11.37.157
- 23.33.238.102
- 20.190.167.19
- 52.110.12.55
- 131.253.33.203
- 52.123.252.233
- 74.178.76.54
- 52.123.252.244
- 72.153.5.133
- 52.123.128.14
- 224.0.0.252
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://cctraff.ru/strik?keyword=caterpillar+c32+generator+manual+pdf
- https://site-1036685.mozfiles.com/files/1036685/zunewuvegew.pdf
- https://site-1037224.mozfiles.com/files/1037224/dotomuwedarisufamilebuzal.pdf
- https://site-1037202.mozfiles.com/files/1037202/97036304863.pdf
- https://site-1036721.mozfiles.com/files/1036721/9736870480.pdf
- https://uploads.strikinglycdn.com/files/51bc21b3-5bf0-4acd-9b32-d78e49d10fec/dasatanewoveziwibo.pdf
- https://site-1037187.mozfiles.com/files/1037187/jexadufik.pdf
- https://site-1036920.mozfiles.com/files/1036920/retudizadi.pdf
- https://site-1037120.mozfiles.com/files/1037120/52536424318.pdf
- https://site-1036945.mozfiles.com/files/1036945/bomawulotepuj.pdf
- https://site-1037057.mozfiles.com/files/1037057/12300937952.pdf
- https://site-1037224.mozfiles.com/files/1037224/dedilegokumazedodumevase.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Embedded domains
- cctraff.ru
- site-1036685.mozfiles.com
- site-1037224.mozfiles.com
- site-1037202.mozfiles.com
- site-1036721.mozfiles.com
- uploads.strikinglycdn.com
- site-1037187.mozfiles.com
- site-1036920.mozfiles.com
- site-1037120.mozfiles.com
- site-1036945.mozfiles.com
- site-1037057.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.110.12.55
- 52.123.252.233
- 74.178.76.54
- 52.123.252.244
- 72.153.5.133
- 52.123.128.14
- 162.159.36.2
- 203.26.79.13
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report