MALICIOUS — 57907846410.pdf
MALICIOUS — 57907846410.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f5d7f8dcecf8760b5e58da3bcec2c6ee7bf4219b89ddc991685f199237dded8b - SHA-1:
29ecc7fc1c223db07815b609f0f3a27f2bd4d6c7 - MD5:
da05d2bbbf4f62b746f49d7b6e31aaa6 - ssdeep:
1536:3GF7p2+non+vN6PWbtDdacvBAPAEN6Z1BDWvyx8nAXk:WF7p2o0WhDAcZAPAs6zEBnz - TLSH:
T19E34BEF3509BED4C768BAF839DE614589088D3896123A7B05588376CC47CAFC7D61AB0 - Submitted as: 57907846410.pdf
- File type: pdf · Size: 56573 bytes
- Verdict: malicious (72/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 72/100 is the fusion of 6 weighted signals:
- Contacted 28 external host(s) at runtime (26 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/51afdec1-3c7f-4a52-84e2-696a1ee9312b/gepikodupazomureta.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=neewer+speedlite+750+ii+manual, https://uploads.strikinglycdn.com/files/51afdec1-3c7f-4a52-84e2-696a1ee9312b/gepikodupazomureta.pdf, https://uploads.strikinglycdn.com/files/b7cf4441-6f52-4833-ae2e-872990eabe1c/vunosemaxevubejenuj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (11 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
8693 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- officeclient.microsoft.com
- www.msn.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
51b3f1a410daee29c5e6dc8caec9ebc64bbe7b80e9d03fe040ceeaee5250944f - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\b5714d2a1473271f161007e13b834e38.png -
f805abe4521dae702be2de574efc8c599e1a1a8d1e94973df1b244a3d28b0ba0
Embedded URLs
- https://gettraff.ru/strik?keyword=neewer+speedlite+750+ii+manual
- https://uploads.strikinglycdn.com/files/51afdec1-3c7f-4a52-84e2-696a1ee9312b/gepikodupazomureta.pdf
- https://uploads.strikinglycdn.com/files/b7cf4441-6f52-4833-ae2e-872990eabe1c/vunosemaxevubejenuj.pdf
- https://uploads.strikinglycdn.com/files/976b91f6-c040-48da-b6d0-4f58bc4626e1/94967377146.pdf
- https://uploads.strikinglycdn.com/files/38f2ad2f-ca93-4b7c-81b5-3c358e5afa54/gulujikelipekexiwiwob.pdf
- https://site-1045384.mozfiles.com/files/1045384/suwoxuluximenelukutevu.pdf
- https://site-1036980.mozfiles.com/files/1036980/91279043952.pdf
- https://site-1042539.mozfiles.com/files/1042539/mevimeba.pdf
- https://site-1038762.mozfiles.com/files/1038762/23280092450.pdf
- https://cdn.shopify.com/s/files/1/0481/2256/0675/files/25cm_x_30cm_in_inches.pdf
- https://cdn.shopify.com/s/files/1/0497/9094/3381/files/bisorofimanuwakevabufozu.pdf
- https://cdn.shopify.com/s/files/1/0500/2500/5206/files/garcinia_free_trial.pdf
- https://cdn.shopify.com/s/files/1/0479/3912/5404/files/xikazez.pdf
- https://cdn.shopify.com/s/files/1/0485/7688/8992/files/61531630413.pdf
- https://site-1036851.mozfiles.com/files/1036851/88515186924.pdf
- https://site-1043032.mozfiles.com/files/1043032/17895631426.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1045384.mozfiles.com
- site-1036980.mozfiles.com
- site-1042539.mozfiles.com
- site-1038762.mozfiles.com
- cdn.shopify.com
- site-1036851.mozfiles.com
- site-1043032.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 74.179.71.159
- 52.168.117.170
- 52.110.12.49
- 52.110.12.40
- 4.144.132.114
- 40.84.97.4
- 4.230.171.124
- 52.230.60.54
- 20.165.94.63
- 135.233.95.135
- 20.42.65.90
- 20.236.44.162
- 52.123.128.14
- 52.123.129.14
- 52.123.252.247
- 135.234.160.244
- 203.26.79.13
- 52.123.252.195
- 74.178.232.29
- 20.42.65.89
- 52.148.114.188
- 4.247.188.233
- 20.42.73.28
- 172.175.111.170
- 72.154.7.108
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report