MALICIOUS — xenebelemozoxojuzoxibaki.pdf
MALICIOUS — xenebelemozoxojuzoxibaki.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100). 2 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
f8d2c52bef0343cafcced602cc4ec6400235ae77abb30adc797aa388fb175728 - SHA-1:
2f3cbbcd774cba456168cd3e014c07eb88ac2ab5 - MD5:
af71b9cb3750bdba83f833c897333f79 - ssdeep:
768:mgGzpDSUxfM1fiZEPFuKKNFx5oGOun89ckoNLisNbQhYY8gum+Q2t9j0nXqRa/lG:zGFGwyiqPFdG2daNQAOXV/Ez - TLSH:
T119327DF30167ED4D3A8BAB83BDE60199604EC689B123D6A015887B2CD57C6FD7F00A51 - Submitted as: xenebelemozoxojuzoxibaki.pdf
- File type: pdf · Size: 43828 bytes
- Verdict: malicious (72/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 72/100 is the fusion of 6 weighted signals:
- Contacted 15 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/7f9cf07e-599d-4240-aff8-09f9440482db/44524508190.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=medita%25C3%25A7%25C3%25A3o+matinal+janelas+para+a+vid, https://cdn.shopify.com/s/files/1/0481/2616/5143/files/aa_fourth_step_fear_inventory.pdf, https://cdn.shopify.com/s/files/1/0429/0835/2679/files/best_wholesale_flowers_san_diego.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (5 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9677 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787780712&P2=404&P3=2&P4=LalcIGqZAxMAsmyVpA1y6QfsLzOT7vsK%2byd2g5h1E5F6JLkaEB%2b%2bnY8hnq2WAVb7zSmZzBoprKl20xDHKPk8zw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787780764&P2=404&P3=2&P4=Xe%2bfwkcikTOFKFhtZm5HLiQucX2PhtV0mcJoR9tTfQTetWxWpZoi65K7Ook9OeMj8MMa5ORkWFL9fdnR53HhhA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787177514&P2=404&P3=2&P4=HIcnzRzzTA9Lvyli3gtrLqzjrILG7BJOP%2fsgIt2BeLKMxWjVY%2fTktfiRiGIBuKKA8OX6b7RsjwkoZwhgr2KL6w%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
e535de30fac7ad04fa7b58773de01258c28afee9f66a0ebad37af9a661f9b74a - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\effacad62b76aa520eaa72109fa71fa5.png -
d65ed24f46780202f9ed762e97012e93d9d53f608711797d4f518f8132f1e76c - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ggtraff.ru/strik?keyword=medita%25C3%25A7%25C3%25A3o+matinal+janelas+para+a+vid
- https://cdn.shopify.com/s/files/1/0496/1904/2455/files/stickman_family_car_decals.pdf
- https://cdn.shopify.com/s/files/1/0481/2616/5143/files/aa_fourth_step_fear_inventory.pdf
- https://cdn.shopify.com/s/files/1/0429/0835/2679/files/best_wholesale_flowers_san_diego.pdf
- https://cdn.shopify.com/s/files/1/0429/0389/6230/files/post_and_courier_obituary_cost.pdf
- https://cdn.shopify.com/s/files/1/0433/0097/8853/files/purchase_terms_and_conditions_template_uk.pdf
- https://cdn.shopify.com/s/files/1/0434/2451/4200/files/rome_parents_guide.pdf
- https://cdn.shopify.com/s/files/1/0428/0313/4627/files/flashpoint_tv_show_episode_guide.pdf
- https://cdn.shopify.com/s/files/1/0432/8282/5376/files/96987960524.pdf
- https://cdn.shopify.com/s/files/1/0431/8124/4577/files/fepawabimamaxe.pdf
- https://cdn.shopify.com/s/files/1/0437/1621/4939/files/physics_vibrations_and_waves_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0434/3290/2806/files/history_timeline_ffa_answers.pdf
- https://cdn.shopify.com/s/files/1/0436/9501/4042/files/cubase_9_activation_code_free.pdf
- https://cdn.shopify.com/s/files/1/0428/2158/3004/files/pimowadixudusexotaforobi.pdf
- https://cdn.shopify.com/s/files/1/0435/8474/9729/files/setozodiwawe.pdf
- https://cdn.shopify.com/s/files/1/0459/6534/4935/files/tatsu_roller_coaster_review.pdf
- https://uploads.strikinglycdn.com/files/7f9cf07e-599d-4240-aff8-09f9440482db/44524508190.pdf
- https://uploads.strikinglycdn.com/files/c24a3354-f6bc-43d0-af86-1dd863c02f30/37019165475.pdf
- https://uploads.strikinglycdn.com/files/3c8ec7e3-5916-4722-80f8-92396495f048/99170429360.pdf
- https://uploads.strikinglycdn.com/files/d8cd4281-d367-4a39-8ecc-40b1c5c20e8b/rawefitidi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 172.215.188.232
- 4.230.171.124
- 20.247.184.142
- 20.184.175.18
- 20.112.250.133
- 74.178.240.61
- 74.179.77.204
- 52.123.129.14
- 40.99.133.242
- 135.233.45.222
- 72.154.7.16
- 203.26.79.13
- 135.234.160.244
- 4.209.250.170
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report