MALICIOUS — 42984762359.pdf
MALICIOUS — 42984762359.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (84/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
fe1253243a5b90fa1060ac2b8b54da7e1c8c1ff1cd206f47ddd91acd7ebbdced - SHA-1:
cf6fb6552ed8733d888f3da0a0888b0742651ee9 - MD5:
7a79618703feec53e64afa164386b733 - ssdeep:
768:XgGzpDnpQib+k0491WumABsxLzLPB6SXXshULrEmuQe13BJbRSqT:wGFzpQAF6zLPAAGULNl83B9RSqT - TLSH:
T1BD327CF310D7ED4C7A8BAB07AEAB119D618AD38C6037D6500584777DC4BC6EC6E00A66 - Submitted as: 42984762359.pdf
- File type: pdf · Size: 45485 bytes
- Verdict: malicious (84/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 84/100 is the fusion of 6 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/214dd8a5-606b-4976-8314-85e0b6280dcd/76694407886.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 18 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=state+theater+portland+oregon, https://uploads.strikinglycdn.com/files/0f94fc19-bedd-4a48-afd6-a04b2b9879b3/pafutolima.pdf, https://uploads.strikinglycdn.com/files/b3ade989-4f3f-4ef4-90d8-9c7b015eab89/zumodulebulolakijo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9748 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\6191f9907766cea4e16614b9ea63ca73.png -
b920c82d5d15e52e26da55ad1190b333618ae239305e1e60608d9c0af8803fc7 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
cb8562f42dbba478a88025fb2a938a72dd361def6f890ccc308c6418cda7b417 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://cctraff.ru/strik?keyword=state+theater+portland+oregon
- https://uploads.strikinglycdn.com/files/0f94fc19-bedd-4a48-afd6-a04b2b9879b3/pafutolima.pdf
- https://uploads.strikinglycdn.com/files/b3ade989-4f3f-4ef4-90d8-9c7b015eab89/zumodulebulolakijo.pdf
- https://uploads.strikinglycdn.com/files/d0bf4af9-ca95-43b8-8871-b313e03d479e/splatoon_inkling_creator.pdf
- https://uploads.strikinglycdn.com/files/67e5abba-05fb-417a-891f-ef6db69eb3b1/39199624685.pdf
- https://uploads.strikinglycdn.com/files/214dd8a5-606b-4976-8314-85e0b6280dcd/76694407886.pdf
- https://uploads.strikinglycdn.com/files/e147277d-010d-48ec-9e79-e4520d38d7e2/roxette_listen_to_your_heart_mp3_320kbps_download.pdf
- https://uploads.strikinglycdn.com/files/252ce419-c517-45f1-9b50-6bac7861c86e/10841023249.pdf
- https://uploads.strikinglycdn.com/files/ebfddb37-07d3-4e5b-b7c1-fd5f554326a5/dikebofewenum.pdf
- https://uploads.strikinglycdn.com/files/51a21fcf-0776-4cc9-b744-a607e9c1276e/ge_microwave_jvm7195skss_owners_manual.pdf
- https://s3.amazonaws.com/farezelof/msbte_academic_calendar_2019-_20.pdf
- https://s3.amazonaws.com/purixifusipelid/34481336322.pdf
- https://s3.amazonaws.com/luxelula/que_es_kabbalah.pdf
- https://uploads.strikinglycdn.com/files/11443954-7491-48e9-88c5-aaeff164a6d1/lebovasus.pdf
- https://uploads.strikinglycdn.com/files/dc70d47e-a563-4ab2-864d-1fe039cc95d4/fidis.pdf
- https://uploads.strikinglycdn.com/files/37b3390d-1ca8-4559-b5e0-ae94d15db3be/bikabuzijejidod.pdf
- https://cdn-cms.f-static.net/uploads/4376379/normal_5f9733fdbc4a9.pdf
- https://cdn-cms.f-static.net/uploads/4368752/normal_5f8d7e4568d04.pdf
- https://cdn-cms.f-static.net/uploads/4385435/normal_5f8d38de26e13.pdf
- https://belujewirozem.weebly.com/uploads/1/3/2/6/132681559/furubapi.pdf
- https://junafoxotoroj.weebly.com/uploads/1/3/0/7/130738975/roxemibemot_fopixuruzutin_xewar.pdf
- https://zusaneji.weebly.com/uploads/1/3/0/8/130813769/8604804.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/5e7030064.pdf
- https://saxibodusazo.weebly.com/uploads/1/3/0/7/130740440/xodirub_jawanolujujal.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- belujewirozem.weebly.com
- junafoxotoroj.weebly.com
- zusaneji.weebly.com
- boguvetasitob.weebly.com
- saxibodusazo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 4.150.223.97
- 72.153.5.135
- 52.168.117.168
- 52.138.229.67
- 172.215.188.225
- 52.123.252.226
- 4.230.171.124
- 74.178.240.51
- 74.178.76.128
- 52.123.129.14
- 40.104.4.2
- 52.123.252.218
- 72.154.7.97
- 203.26.79.13
- 52.123.252.224
- 172.178.240.163
- 4.209.250.170
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report