MALICIOUS — swift_handbook.pdf
MALICIOUS — swift_handbook.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
f0ad414421f86a0973a0aab73afdf6fd58a93334294f6ef2df01b2358336d127 - SHA-1:
1771fa60e380294807ce67cb0b3b874dc1abe080 - MD5:
658734d9daafc81e407501e9e303b5cd - ssdeep:
1536:EGFBeqYRukahZNZ/fPpesOWhVu/ZwGu1JIE:RFBeDudZfvOWhV0wGuj - TLSH:
T182348EF31097ED8D368BEB03AEB70169A18AC34961269760549C772CC5BC6FD3F00A55 - Submitted as: swift_handbook.pdf
- File type: pdf · Size: 52361 bytes
- Verdict: malicious (86/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 86/100 is the fusion of 7 weighted signals:
- Memory forensics: 3 finding(s), e.g. RWX/private injected region in SumatraPDF.exe (pid 8608) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Contacted 18 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/64a05c81-f031-4e51-bf5b-7001436bd584/jibematamadifasesuwivixu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=swift+handbook+pdf, https://cdn-cms.f-static.net/uploads/4366949/normal_5f883833b67fb.pdf, https://cdn-cms.f-static.net/uploads/4376874/normal_5f8a2e6ae1c4a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (15 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9700 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- c.pki.goog
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 255.255.254.169.in-addr.arpa
- 79.243.254.169.in-addr.arpa
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
3a9786b45bea5354aa748db180a69517fe648a7e586f5ddc846a2bd99ab5cec6 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\7c16535036658d634da1e5a2aed95622.png -
eb4e15d1f9da108d10fc6a769de0fcdee017db698932b4da71c2c06a19c1c982 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://gettraff.ru/strik?keyword=swift+handbook+pdf
- https://cdn-cms.f-static.net/uploads/4366949/normal_5f883833b67fb.pdf
- https://cdn-cms.f-static.net/uploads/4376874/normal_5f8a2e6ae1c4a.pdf
- https://cdn-cms.f-static.net/uploads/4366348/normal_5f8b7a616b83c.pdf
- https://cdn-cms.f-static.net/uploads/4383451/normal_5f8ccdb7966c4.pdf
- https://cdn-cms.f-static.net/uploads/4377408/normal_5f8b82e57a401.pdf
- https://uploads.strikinglycdn.com/files/64a05c81-f031-4e51-bf5b-7001436bd584/jibematamadifasesuwivixu.pdf
- https://uploads.strikinglycdn.com/files/db4e05c7-a3e2-4748-8945-df9c6f7cff44/sudomuvizawunabimotetide.pdf
- https://uploads.strikinglycdn.com/files/3abb0513-d450-4c62-a8d2-09338ee9b5ed/85099625980.pdf
- https://uploads.strikinglycdn.com/files/54d74b3c-e13d-4fb1-be99-6f94d2e70dbb/12658446535.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/limin_razubutakuxot_pepaxakofotes_mofaka.pdf
- https://wuwenivavubujer.weebly.com/uploads/1/3/1/4/131437756/kolulubin.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/mezevoxinokimuwamibu.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/3731638.pdf
- https://femitinekabel.weebly.com/uploads/1/3/1/4/131437683/1694331.pdf
- https://uploads.strikinglycdn.com/files/442c82a0-2116-4ff7-ab10-cd279b929414/tipunopuzu.pdf
- https://uploads.strikinglycdn.com/files/181c1246-2ce5-4909-b99e-ff0fe2c8efbb/error_tipo_1_y_2_ejercicios_resueltos.pdf
- https://uploads.strikinglycdn.com/files/d7ed9b9c-35b8-4bcf-879e-1b40f8c766fc/47990972049.pdf
- https://uploads.strikinglycdn.com/files/c442fbe5-4a0c-4663-adfa-1d4f724cb12a/kuramedew.pdf
- https://uploads.strikinglycdn.com/files/980431a2-0965-4d70-895e-6725b6e9ec61/97974294469.pdf
- https://topodomero.weebly.com/uploads/1/3/2/6/132696018/d4942bd0ec9686.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/6431815.pdf
- https://pukotegifo.weebly.com/uploads/1/3/0/8/130874060/3248992.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/8276696.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- besiwalufeg.weebly.com
- wuwenivavubujer.weebly.com
- xojerajap.weebly.com
- gimejexoxixaza.weebly.com
- femitinekabel.weebly.com
- topodomero.weebly.com
- jakedekokobara.weebly.com
- pukotegifo.weebly.com
- jatorogerujew.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 20.42.73.25
- 20.165.94.63
- 135.232.92.137
- 20.42.65.88
- 20.184.175.1
- 52.110.12.38
- 74.179.77.204
- 4.230.171.124
- 57.154.63.210
- 20.76.201.171
- 52.123.128.14
- 74.178.232.29
- 203.26.79.13
- 172.178.240.162
- 57.155.101.212
- 52.123.252.224
- 52.123.252.225
- 142.250.183.35
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report