MALICIOUS — vapaja.pdf
MALICIOUS — vapaja.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 53 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
dd11fd99b9d2980f7b3a37f8feabc8684657340bc4e8d3c18e8b21e90c0e5672 - SHA-1:
f0d6b213a57b0b5d31f55db67d180a5a7cff0d2f - MD5:
82fa45154f58a674ad7f989130734800 - ssdeep:
1536:WGFKLdN7Gptyf1x62dmv8DyiZfsRwkLY:vFKLf8eXzhDyilsRw3 - TLSH:
T1D8349FF760A7EC4C7B4B6F07AABF1269508AD68960329760448C776DD4B86FE3F00950 - Submitted as: vapaja.pdf
- File type: pdf · Size: 55725 bytes
- Verdict: malicious (75/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 7 weighted signals:
- Contacted 17 external host(s) at runtime (2 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/d2fd976c-a063-41d2-8db0-9c098f560b92/zelefuluba.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=antigone+play+script+summary, https://uploads.strikinglycdn.com/files/d2fd976c-a063-41d2-8db0-9c098f560b92/zelefuluba.pdf, https://uploads.strikinglycdn.com/files/5ce5e2b6-2866-48a2-b022-76a1b29bb44e/4150049572.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9751 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 255.255.254.169.in-addr.arpa
- 79.243.254.169.in-addr.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
19d4a0413eecfc397bb0235358fd3fae3df7d7653e2be3f62ea5cb24d963ac36 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\8f8a8782c196b8f3e12cc90bbdfc702f.png -
55c5efbb167f403a040479c1a24d7d7fc79e8bf71f3d3145fc4631f0017b8ba0 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://gettraff.ru/strik?keyword=antigone+play+script+summary
- https://uploads.strikinglycdn.com/files/d2fd976c-a063-41d2-8db0-9c098f560b92/zelefuluba.pdf
- https://uploads.strikinglycdn.com/files/5ce5e2b6-2866-48a2-b022-76a1b29bb44e/4150049572.pdf
- https://s3.amazonaws.com/zuxadol/introduction_to_forensic_and_criminal_psychology_6th_edition.pdf
- https://cdn-cms.f-static.net/uploads/4366980/normal_5f87f4c848463.pdf
- https://uploads.strikinglycdn.com/files/8d503de9-e12d-4ebe-9ed0-4020820d5a26/fomepirelos.pdf
- https://cdn-cms.f-static.net/uploads/4378604/normal_5f8fb88278e6e.pdf
- https://s3.amazonaws.com/gupuso/bukenolapateralod.pdf
- https://cdn-cms.f-static.net/uploads/4368770/normal_5f90e64501548.pdf
- https://uploads.strikinglycdn.com/files/61fe894e-6cfc-45fd-bf4b-4c431175af6d/pezedabogoxipawalefajak.pdf
- https://cdn-cms.f-static.net/uploads/4388820/normal_5f8dfdd12f27d.pdf
- https://cdn-cms.f-static.net/uploads/4373998/normal_5f945549ec079.pdf
- https://uploads.strikinglycdn.com/files/b8032020-0ce7-458e-9822-a4f8af08f20c/pimajawur.pdf
- https://cdn-cms.f-static.net/uploads/4376612/normal_5f937d21492c0.pdf
- https://cdn-cms.f-static.net/uploads/4416128/normal_5f970bd3970cf.pdf
- https://cdn-cms.f-static.net/uploads/4387939/normal_5f90a285b6373.pdf
- https://uploads.strikinglycdn.com/files/89901b18-998a-4001-a7da-f59214267962/8578678025.pdf
- https://uploads.strikinglycdn.com/files/b0ed5949-22e9-4494-aa19-2b57666b63ff/prueba_de_oxidasa_fundamento.pdf
- https://s3.amazonaws.com/towakog/jisibopevunogetonofefepek.pdf
- https://s3.amazonaws.com/peveziwoguxuzam/winter_soldier_hoodie.pdf
- https://s3.amazonaws.com/fatisake/company_profile_presentation_sample.pdf
- https://uploads.strikinglycdn.com/files/c2cd14a6-16aa-429d-8e36-fdc6980d6174/rivinuvubejesigerurulefo.pdf
- https://uploads.strikinglycdn.com/files/0b8b5a08-8294-44dd-beeb-08f18138f2a5/counter_strike_1._6_server_indir.pdf
- https://s3.amazonaws.com/bezutu/fofipikijala.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 74.178.76.128
- 72.145.35.102
- 135.233.95.144
- 52.123.129.14
- 135.232.92.34
- 52.110.12.44
- 20.247.184.142
- 4.230.171.124
- 72.145.35.108
- 203.26.79.13
- 20.42.72.131
- 74.178.76.54
- 52.123.252.193
- 172.178.240.161
- 52.123.252.203
- 52.148.114.188
- 40.99.134.18
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report