MALICIOUS — rowavivadepimuse.pdf
MALICIOUS — rowavivadepimuse.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (80/100). 2 of 50 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
d23476509d427df43d17b62f5434188efb839fbee0ef0db5e4f2a2334192eaba - SHA-1:
f05e62d5ca8a95db2979d167580056688ae84e44 - MD5:
d77f43ee0cb6491af65253b2f79fffee - ssdeep:
768:7gGzpDEpzzX+XO7VVBtD/FnritYLfNaizKwpUi1JXV14Lt:EGFYpzcyV7JNamp7Jn4Lt - TLSH:
T1CA316DF35097ED4C7A8FAB83AD7A1199A14AC6887037976009CC771C84B86FD7F11A60 - Submitted as: rowavivadepimuse.pdf
- File type: pdf · Size: 39668 bytes
- Verdict: malicious (80/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 80/100 is the fusion of 7 weighted signals:
- Embedded link rated malicious by URL analysis: https://rolosakuzorega.weebly.com/uploads/1/3/1/3/131379035/c55c8.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=chestnut%20hero%20of%20central%20park%20full%20m, https://uploads.strikinglycdn.com/files/e38ed4a5-bf09-4fd8-b122-da5e4414ac1a/85612833333.pdf, https://uploads.strikinglycdn.com/files/2deded54-e3a8-4fd5-b419-3ed6739a8e16/tefesirifunopakumuzafanul.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 12 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9604 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 255.255.254.169.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 251.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep(3)._dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
eb0c12c44b1137745cb51b0e09c27383104902773296ea5978ed63722e1dd003 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\3dbe19512514c3b84cb57171e202889a.png -
eb93259a3124ca3b8845e5ab6eab7bbf7b25cf2372dd5122a25e58df3fc2bbae - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ggtraff.ru/wb?keyword=chestnut%20hero%20of%20central%20park%20full%20m
- https://uploads.strikinglycdn.com/files/e38ed4a5-bf09-4fd8-b122-da5e4414ac1a/85612833333.pdf
- https://uploads.strikinglycdn.com/files/2deded54-e3a8-4fd5-b419-3ed6739a8e16/tefesirifunopakumuzafanul.pdf
- https://uploads.strikinglycdn.com/files/a84eddff-68dc-4582-8e67-05880b36ddee/58014017751.pdf
- https://uploads.strikinglycdn.com/files/a2779049-8211-489e-a578-1bbe4b5d9497/dekegojomodinem.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f87561aee302.pdf
- https://cdn-cms.f-static.net/uploads/4367937/normal_5f882b1f41fba.pdf
- https://rolosakuzorega.weebly.com/uploads/1/3/1/3/131379035/c55c8.pdf
- https://mojenosude.weebly.com/uploads/1/3/1/3/131382274/55dff.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/1d1f8ecc085ca.pdf
- https://uploads.strikinglycdn.com/files/6535b766-463b-4ecc-8fd5-36e46157c0d5/kedibusuxebibasenoxerasi.pdf
- https://uploads.strikinglycdn.com/files/66cb5fa8-e5d0-42ff-bb9b-a72895e1339d/44065874374.pdf
- https://uploads.strikinglycdn.com/files/665d3611-3a8f-4223-afc8-99cc5482f130/6190092982.pdf
- https://uploads.strikinglycdn.com/files/d80bef15-ed6c-4625-b2c5-a17f0ee2e91f/gowedidodiwij.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/pasifoxixugererupew.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/gapovowumepekegosiza.pdf
- https://tiwilofudux.weebly.com/uploads/1/3/1/6/131606348/razavipo.pdf
- https://pepotoxuxomupav.weebly.com/uploads/1/3/1/4/131483830/99774e40eb.pdf
- https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/vizuriziwanuw-musovufakepaba-kazujoxux-labulele.pdf
- https://cdn-cms.f-static.net/uploads/4365642/normal_5f885e8473a9a.pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f88546d771e3.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- rolosakuzorega.weebly.com
- mojenosude.weebly.com
- mogilifus.weebly.com
- mojivimimujovo.weebly.com
- genigudepa.weebly.com
- tiwilofudux.weebly.com
- pepotoxuxomupav.weebly.com
- kabudededawizo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 20.184.175.20
- 52.110.12.55
- 20.42.179.204
- 4.230.171.124
- 52.182.143.212
- 74.178.76.128
- 74.179.71.159
- 52.168.112.67
- 4.144.132.223
- 92.223.78.30
- 162.159.36.2
- 203.26.79.13
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report