MALICIOUS — b126918.pdf
MALICIOUS — b126918.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
e125a1a6613f4a62f5dd8c17362bf574b0f02d8e05d74825c29e0c769041cf19 - SHA-1:
0f3b43c7b518a79a52cbe045ecf0a840657b5dd8 - MD5:
85faf0959b9a2a62b0ad6a7f9a1f912b - ssdeep:
1536:tGFMeRbI5kIq4Dw41MGiHjObBW6/I+IGksIo:wFMeRboq4Dw41MJDk3I+IGkU - TLSH:
T1C735BFF31157DDCC7B8AEB03ADA7011A6545DB8C6132AA5045887B7CC9BCAFD3E20690 - Submitted as: b126918.pdf
- File type: pdf · Size: 59636 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 7 weighted signals:
- Contacted 14 external host(s) at runtime (2 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/763ae063-6b40-49d8-8ce1-1b71aaba1809/2394869955.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=brave%20frontier%20i%20already%20did%20the%202.2, https://uploads.strikinglycdn.com/files/763ae063-6b40-49d8-8ce1-1b71aaba1809/2394869955.pdf, https://uploads.strikinglycdn.com/files/be12ad70-b531-4495-9bdc-a4582e7e4785/jozul.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9787 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
c5b90611834b7d539b729eaaf51f3a742d08699cd371076c4dd689e27ff11122 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\012529713300468374c62b0ee2bc14d0.png -
f5d66ce65414345a908f4fa45c030e1d040e0a62a54ad5f5088caf895e6d2dff - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://cctraff.ru/wb?keyword=brave%20frontier%20i%20already%20did%20the%202.2
- https://uploads.strikinglycdn.com/files/763ae063-6b40-49d8-8ce1-1b71aaba1809/2394869955.pdf
- https://uploads.strikinglycdn.com/files/be12ad70-b531-4495-9bdc-a4582e7e4785/jozul.pdf
- https://uploads.strikinglycdn.com/files/3f14433b-e979-424f-a347-85aefb2d9477/fobexizegovojosal.pdf
- https://uploads.strikinglycdn.com/files/eac1c5d0-2b82-42dd-a666-477a3ed28d64/26591761787.pdf
- https://zirufifun.weebly.com/uploads/1/3/0/8/130874679/1ab64.pdf
- https://cdn.shopify.com/s/files/1/0435/6639/9647/files/19957184235.pdf
- https://cdn.shopify.com/s/files/1/0499/5088/4008/files/werbung_blockieren_android_handy.pdf
- https://cdn.shopify.com/s/files/1/0498/6473/6957/files/gumul.pdf
- https://cdn.shopify.com/s/files/1/0485/0689/6539/files/pezamopiwizixajefugisi.pdf
- https://cdn.shopify.com/s/files/1/0430/8451/3444/files/royal_envoy_2_walkthrough_level_63.pdf
- https://cdn.shopify.com/s/files/1/0499/8958/2998/files/whirlpool_e1_f2_error_code.pdf
- https://cdn-cms.f-static.net/uploads/4366995/normal_5f87e14df2964.pdf
- https://cdn-cms.f-static.net/uploads/4366956/normal_5f880b352e5a6.pdf
- https://cdn-cms.f-static.net/uploads/4367005/normal_5f8731c359d09.pdf
- https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/4765241.pdf
- https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/6419222.pdf
- https://fidegobopoj.weebly.com/uploads/1/3/2/8/132815019/fobipit_nigumexazi_duxiwezixas.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- zirufifun.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- jawowigo.weebly.com
- mupibidegupek.weebly.com
- fidegobopoj.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 135.233.95.144
- 57.154.63.210
- 20.89.1.8
- 52.110.12.55
- 52.110.12.25
- 20.247.184.197
- 4.230.171.124
- 20.236.44.162
- 74.178.240.61
- 135.233.45.222
- 135.232.92.34
- 52.123.129.14
- 203.26.79.13
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report