MALICIOUS — 90d19e_424b5b9c565849eb9d3630e8547c5a0e.pdf
MALICIOUS — 90d19e_424b5b9c565849eb9d3630e8547c5a0e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e8962d8c1910aaf96889cd9f285c208c195381eaf27542a369dd4acad6e066d7 - SHA-1:
3e6afdb25aa043fc11658dcfde67f0868711f36f - MD5:
f4cf03b603a71ea39777b2c4af559c85 - ssdeep:
768:GsgGzpDvthxKFWWszZdqdfZkuBO1EFZSP4EscS7W1eaP6/rLVAh9thpJK/QcXgk4:aGFLt3K0WUzqZ9OOpB1rVAh9tFs1gkn4 - TLSH:
T100329EF30167ED4C6B8EAB07ADD91149A146C28E6033A76044D8776CC5BC6FDAF11E22 - Submitted as: 90d19e_424b5b9c565849eb9d3630e8547c5a0e.pdf
- File type: pdf · Size: 44593 bytes
- Verdict: malicious (89/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 89/100 is the fusion of 8 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.ru/wix?keyword=computer+networks+and+internets+5th+edition+pdf, https://59b3bd42-89ed-40df-ae5e-f0cb3d73e663.filesusr.com/ugd/5ea691_9777379ad7184cdcaff9d3c09325c513.pdf?index=true, https://a71f5d54-e840-432d-b970-129a0e1b7872.filesusr.com/ugd/717a42_704965c451eb45f3bb9e3bb4d2091e21.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 5 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (12 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1064 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- searchapp.bundleassets.example
- teams.cloud.microsoft
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- 23.40.52.209
- 162.159.142.9 US · San Francisco · AS13335 Cloudflare, Inc.
- 74.179.71.159 US · Moses Lake · AS8075 Microsoft Corporation
- 192.168.122.115
- 23.33.238.106
- 52.123.252.197 AU · Sydney · AS8075 Microsoft Corporation
- 23.221.133.185
- 74.179.77.204 US · Moses Lake · AS8075 Microsoft Corporation
- 23.33.238.194
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 224.0.0.252
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ttraff.ru/wix?keyword=computer+networks+and+internets+5th+edition+pdf
- https://59b3bd42-89ed-40df-ae5e-f0cb3d73e663.filesusr.com/ugd/5ea691_9777379ad7184cdcaff9d3c09325c513.pdf?index=true
- https://a71f5d54-e840-432d-b970-129a0e1b7872.filesusr.com/ugd/717a42_704965c451eb45f3bb9e3bb4d2091e21.pdf?index=true
- https://ed3f1e17-e224-41a3-b994-c4237c37d36a.filesusr.com/ugd/035627_09b0c8fa7c634b858d2373c9c226bb02.pdf?index=true
- https://fd82d4f6-2364-496b-aeb7-3f263ba29393.filesusr.com/ugd/938c70_c0e3d2537beb4b128bf1fd3d693b30d9.pdf?index=true
- https://2835d592-ed9e-459e-ba2c-3e5da2d8dec4.filesusr.com/ugd/db93e9_8968f9a948de417290d8518bd536ed1f.pdf?index=true
- https://1e23c6c1-8353-4330-8201-30fb12d5e459.filesusr.com/ugd/625844_db26f6fd97b24eb7b488c99b67dc7bdb.pdf?index=true
- https://c3b367ca-c7e3-4be7-9e24-f359b464476d.filesusr.com/ugd/65b209_86451bed7d03422dba838fb5c7982d33.pdf?index=true
- https://9b74b398-4aac-4fd7-b33a-c647dac2e41a.filesusr.com/ugd/48f461_ee17d6c002e8465c98e820f18b0cce87.pdf?index=true
- http://files.gruffcorn13.com/uploads/1/3/0/9/130969728/9042446.pdf
- http://jusotid.jropro.com/uploads/1/3/0/7/130775722/komafa-nunekosutotasin-kuxisuraviwupa-pupuxamimiwefa.pdf
- http://xuxuwowi.christineomalley.com/uploads/1/3/0/8/130874276/4bcf4f706.pdf
- https://cdn.shopify.com/s/files/1/0434/3565/5335/files/nourishing_extract_monster_hunter_wo.pdf
- https://cdn.shopify.com/s/files/1/0433/2892/9960/files/25484178754.pdf
- https://cdn.shopify.com/s/files/1/0451/4299/9194/files/aggregate_demand_and_supply_curve.pdf
- https://cdn.shopify.com/s/files/1/0432/8793/7179/files/99051832546.pdf
- https://cdn.shopify.com/s/files/1/0429/5481/7690/files/dewovaw.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Embedded domains
- ttraff.ru
- 59b3bd42-89ed-40df-ae5e-f0cb3d73e663.filesusr.com
- a71f5d54-e840-432d-b970-129a0e1b7872.filesusr.com
- ed3f1e17-e224-41a3-b994-c4237c37d36a.filesusr.com
- fd82d4f6-2364-496b-aeb7-3f263ba29393.filesusr.com
- 2835d592-ed9e-459e-ba2c-3e5da2d8dec4.filesusr.com
- 1e23c6c1-8353-4330-8201-30fb12d5e459.filesusr.com
- c3b367ca-c7e3-4be7-9e24-f359b464476d.filesusr.com
- 9b74b398-4aac-4fd7-b33a-c647dac2e41a.filesusr.com
- files.gruffcorn13.com
- jusotid.jropro.com
- xuxuwowi.christineomalley.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 162.159.142.9
- 74.179.71.159
- 52.123.252.197
- 74.179.77.204
- 4.230.171.124
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report