MALICIOUS — e0d0cf_41ffb49b6c5542da98cb8155a8fa3d4e.pdf
MALICIOUS — e0d0cf_41ffb49b6c5542da98cb8155a8fa3d4e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e3a8bc0f9e3874580d131bc5b7588d51c1de63004f4fa10ae9d89176f67faf7e - SHA-1:
eebce5bbf50e6d32bfdd0a6ac1413ff604cde754 - MD5:
0715781e0c4ecf17209bac32a6b9e782 - ssdeep:
768:tmgGzpDGdd/fBCfFjjaPdeVkZ403nDTLoHgn88xtXI5W4HwG+B9:pGFq/fyjWXTqgl6V1+B9 - TLSH:
T1CB319EF31163EC4C7A839B177EEA255E904AD9892132F5B449983B7DD47C3BDAE00920 - Submitted as: e0d0cf_41ffb49b6c5542da98cb8155a8fa3d4e.pdf
- File type: pdf · Size: 42908 bytes
- Verdict: malicious (89/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 89/100 is the fusion of 8 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.cc/wix?keyword=probability+concepts+in+engineering+and+2nd+edition+pdf, https://cce26f99-4045-4818-9c58-10d02d5a12ad.filesusr.com/ugd/2c8d66_2e0d796412fa4d85b2297afff22a9283.pdf?index=true, https://5ee7b3d5-bbd3-448e-b957-581b7710e961.filesusr.com/ugd/7d1dc9_56f65d63c1c04a06b1b45860f76fe4e9.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 9 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (12 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1007 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- searchapp.bundleassets.example
- teams.cloud.microsoft
- ntp.ubuntu.com
- http://rb.symcb.com/rb.crl
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/b44b0279-d0c2-4f15-af86-e5757d0bddab/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- 52.123.252.246 AU · Sydney · AS8075 Microsoft Corporation
- 52.110.12.40 AU · Sydney · AS8075 Microsoft Corporation
- 52.123.129.14 US · Redmond · AS8075 Microsoft Corporation
- 23.33.238.119
- 23.40.52.85
- 52.123.252.226 AU · Sydney · AS8075 Microsoft Corporation
- 135.232.92.34 US · Boydton · AS8075 Microsoft Limited
- 72.145.35.102 IE · Dublin · AS8075 Microsoft Corporation
- 23.221.133.223
- 23.11.37.157
- 23.33.238.208
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ttraff.cc/wix?keyword=probability+concepts+in+engineering+and+2nd+edition+pdf
- https://cce26f99-4045-4818-9c58-10d02d5a12ad.filesusr.com/ugd/2c8d66_2e0d796412fa4d85b2297afff22a9283.pdf?index=true
- https://5ee7b3d5-bbd3-448e-b957-581b7710e961.filesusr.com/ugd/7d1dc9_56f65d63c1c04a06b1b45860f76fe4e9.pdf?index=true
- https://985e6220-25cf-4ee2-9780-80d77ecfb547.filesusr.com/ugd/33ab24_75f6673416f642ebb13020a873998083.pdf?index=true
- https://da139401-e57c-4a04-9c3b-3ed5a9edf262.filesusr.com/ugd/bb05c1_b1c6ee13fc384789af0057973d3ce52b.pdf?index=true
- https://78a67bab-d466-4c5e-98a3-0631a0de88dd.filesusr.com/ugd/3d514e_94ab779c2ff842a3838b816446a09dab.pdf?index=true
- http://files.thebodyserve.com/uploads/1/3/1/6/131637649/37841e4d626688.pdf
- http://tufatal.nicholasruscettaart.com/uploads/1/3/0/7/130738546/843105.pdf
- https://cdn.shopify.com/s/files/1/0434/3290/2823/files/february_days_python.pdf
- https://cdn.shopify.com/s/files/1/0434/5207/2086/files/fallout_4_autumn_overhaul.pdf
- https://cdn.shopify.com/s/files/1/0432/6385/2712/files/how_to_reset_a_dometic_dual_zone_thermostat.pdf
- https://cdn.shopify.com/s/files/1/0432/4117/7252/files/wekefezanina.pdf
- https://16bb678a-3085-4afc-aa11-06bd5180a027.filesusr.com/ugd/2e16aa_d305a0b9022245298918b88634f38d8c.pdf?index=true
- https://bf1948cf-17dd-4771-a100-12875e3267c2.filesusr.com/ugd/4b874d_be4d7d3ea3b44f1fa655e5988a04fb08.pdf?index=true
- https://8d2963e9-1f03-4fba-adb1-c434a32a6fd7.filesusr.com/ugd/b0b521_13db4717ca2841d4b81bda1342f5004c.pdf?index=true
- https://d31f71fd-f358-45c7-97cd-cc71c387a50d.filesusr.com/ugd/64bd79_909ae1b971104325abc73045617ba287.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://rb.symcb.com/rb.crl
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/b44b0279-d0c2-4f15-af86-e5757d0bddab/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Embedded domains
- ttraff.cc
- cce26f99-4045-4818-9c58-10d02d5a12ad.filesusr.com
- 5ee7b3d5-bbd3-448e-b957-581b7710e961.filesusr.com
- 985e6220-25cf-4ee2-9780-80d77ecfb547.filesusr.com
- da139401-e57c-4a04-9c3b-3ed5a9edf262.filesusr.com
- 78a67bab-d466-4c5e-98a3-0631a0de88dd.filesusr.com
- files.thebodyserve.com
- tufatal.nicholasruscettaart.com
- cdn.shopify.com
- 16bb678a-3085-4afc-aa11-06bd5180a027.filesusr.com
- bf1948cf-17dd-4771-a100-12875e3267c2.filesusr.com
- 8d2963e9-1f03-4fba-adb1-c434a32a6fd7.filesusr.com
- d31f71fd-f358-45c7-97cd-cc71c387a50d.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.123.252.246
- 52.110.12.40
- 52.123.129.14
- 52.123.252.226
- 135.232.92.34
- 72.145.35.102
- 203.26.79.13
- 20.89.1.11
- 162.159.36.2
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report