MALICIOUS — vineni.pdf
MALICIOUS — vineni.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100). 2 of 50 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
e6d57df20ebeb99b41fed779198c7b1cd91dfef6ad852b23699c620e7207292c - SHA-1:
e31208c59f6c270f103a9570742a5f85e3963847 - MD5:
e3774b708cab94140ba9f694911196c0 - ssdeep:
1536:0GFhpP1hhF1m6XSO3DmopdfcD2siSRw7K5d2NjE3mxXzj/1:BFhp9hhLnbDfc9z4K5kjm2XF - TLSH:
T1E538C0F300A7EE4D6987EF076AEB149C814AE3485073A7944495773CC0BC6BEAF11A61 - Submitted as: vineni.pdf
- File type: pdf · Size: 79005 bytes
- Verdict: malicious (93/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 93/100 is the fusion of 8 weighted signals:
- Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Contacted 41 external host(s) at runtime (7 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/1972a037-980f-4bc1-8210-106c9909d28b/bazojuvonoxexik.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=danny+phantom+mixtoon, https://site-1037902.mozfiles.com/files/1037902/vopowo.pdf, https://site-1039207.mozfiles.com/files/1039207/1296460843.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9730 behavior events · 1 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- /opt/CAPEv2/storage/analyses/31746/files/38012da394c23dbdc6166532da13d9896e5de0a1d885285e3577325615a59e45 -
38012da394c23dbdc6166532da13d9896e5de0a1d885285e3577325615a59e45 - /opt/CAPEv2/storage/analyses/31746/files/488f87d65c5a9c30be8d3809007a799ca1a2675cdeb70902aec989486881f83c -
488f87d65c5a9c30be8d3809007a799ca1a2675cdeb70902aec989486881f83c - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.wnGdRF7YN1 -
be70d8e582e22262b36dfafd82e0144dd1773da322cf01d31319a3b2634032f7
Embedded URLs
- https://gettraff.ru/strik?keyword=danny+phantom+mixtoon
- https://site-1037902.mozfiles.com/files/1037902/vopowo.pdf
- https://site-1039207.mozfiles.com/files/1039207/1296460843.pdf
- https://site-1048557.mozfiles.com/files/1048557/67207683173.pdf
- https://site-1038840.mozfiles.com/files/1038840/rubimefinod.pdf
- https://site-1036879.mozfiles.com/files/1036879/xafabi.pdf
- https://uploads.strikinglycdn.com/files/1972a037-980f-4bc1-8210-106c9909d28b/bazojuvonoxexik.pdf
- https://uploads.strikinglycdn.com/files/5ee2a1d7-2e39-4659-96d8-dd6a96e2bc1a/26685084447.pdf
- https://uploads.strikinglycdn.com/files/e3a1b7b9-6477-45b0-b980-8aa42540456f/92567263653.pdf
- https://uploads.strikinglycdn.com/files/50d1f4d5-0326-4578-9846-74e6fbf1eca4/nolegafonafumoda.pdf
- https://uploads.strikinglycdn.com/files/12428929-04c5-4353-b6df-38d0738aa925/30013525980.pdf
- https://site-1039529.mozfiles.com/files/1039529/pazetetanewovukewibam.pdf
- https://site-1038520.mozfiles.com/files/1038520/nigidib.pdf
- https://site-1044103.mozfiles.com/files/1044103/79251686439.pdf
- https://site-1038387.mozfiles.com/files/1038387/36379866981.pdf
- https://site-1037111.mozfiles.com/files/1037111/bezanevetig.pdf
- https://uploads.strikinglycdn.com/files/f904a3c7-6566-4e60-b873-445961fb4e1e/39249121494.pdf
- https://uploads.strikinglycdn.com/files/96e732bc-d2d0-4b14-a601-a0174c4985f0/87701525237.pdf
- https://uploads.strikinglycdn.com/files/b60350b8-0758-44b9-a30e-a36936b9e4eb/72947854656.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1037902.mozfiles.com
- site-1039207.mozfiles.com
- site-1048557.mozfiles.com
- site-1038840.mozfiles.com
- site-1036879.mozfiles.com
- uploads.strikinglycdn.com
- site-1039529.mozfiles.com
- site-1038520.mozfiles.com
- site-1044103.mozfiles.com
- site-1038387.mozfiles.com
- site-1037111.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 4.150.223.100
- 135.233.95.144
- 57.155.104.224
- 135.232.92.34
- 52.110.12.56
- 52.110.12.37
- 52.230.59.222
- 4.230.171.124
- 203.26.79.13
- 13.89.179.12
- 20.231.239.246
- 74.178.240.61
- 40.103.64.226
- 52.123.129.14
- 52.123.128.14
- 40.104.4.2
- 20.165.94.46
- 92.223.78.30
- 74.179.77.204
- 172.175.111.170
- 20.42.65.88
- 142.250.195.227
File paths
- k:\K+GS
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report