MALICIOUS — 384ea4_a4801e24ba4842ada097278a33275782.pdf
MALICIOUS — 384ea4_a4801e24ba4842ada097278a33275782.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fff1ed338e3f2159d61ec7cd52e4c6be2ca6f52a3dd4cda498c325e2971dca6c - SHA-1:
7e59632cdfbfa8f22a5f4b187b542049cfec0f26 - MD5:
a40c363435f24a2e75799ce5c31bf221 - ssdeep:
768:ngGzpDJoqVW/SCbO/bqLUttFN0i5tQhYS+wT5EmZW5QwB:gGF9oE/lt9PtaYS+s5EmZWSwB - TLSH:
T1C731AEFB1067ED8C769A6F03AEDB164D9045C7CE2122967059C87B2CD47C2ED6E01A32 - Submitted as: 384ea4_a4801e24ba4842ada097278a33275782.pdf
- File type: pdf · Size: 42552 bytes
- Verdict: malicious (89/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 89/100 is the fusion of 8 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.link/wix?keyword=motor+labor+guide+free, https://a86a66e0-de0f-46b7-87a0-1e227422e571.filesusr.com/ugd/895bef_72493e1ca2fb45bc896dbecedca6f67d.pdf?index=true, https://a0265a74-d679-40c0-911f-4c7722f8432b.filesusr.com/ugd/682d1c_c0eb4190d7814093b444c277ec12abe5.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 5 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (14 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1033 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- searchapp.bundleassets.example
- teams.cloud.microsoft
- outlook.office.com
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- 23.40.52.209
- 20.190.142.167
- 23.11.37.157
- 23.33.238.109
- 52.123.252.220 AU · Sydney · AS8075 Microsoft Corporation
- 92.223.78.30 AU · Sydney · AS199524 G-Core Labs Customer assignment
- 20.165.94.46 US · San Antonio · AS8075 Microsoft Corporation
- 204.79.197.203
- 135.232.92.137 US · Boydton · AS8075 Microsoft Limited
- 150.171.27.11
- 23.221.133.223
- 151.101.30.172
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ttraff.link/wix?keyword=motor+labor+guide+free
- https://a86a66e0-de0f-46b7-87a0-1e227422e571.filesusr.com/ugd/895bef_72493e1ca2fb45bc896dbecedca6f67d.pdf?index=true
- https://a0265a74-d679-40c0-911f-4c7722f8432b.filesusr.com/ugd/682d1c_c0eb4190d7814093b444c277ec12abe5.pdf?index=true
- https://050d644b-d873-49df-9a6d-d5088ff45ac6.filesusr.com/ugd/3ed902_c2c02ea596c143d6a9db43ba7d61ab24.pdf?index=true
- https://255f2204-478e-4d84-ad84-c15daad8613b.filesusr.com/ugd/bc79a4_ca5bbf185bc84e1abd38c63bca5db9d6.pdf?index=true
- https://da514abc-7b9c-4886-bc8b-a479a601caa1.filesusr.com/ugd/73cb9e_86ee65df3efe450988efd118540407ae.pdf?index=true
- https://12839eed-907b-4bf1-88ba-dd8ea023d9f5.filesusr.com/ugd/93c935_685c07658f634c5b831855d88c3f45d6.pdf?index=true
- http://files.samuelpakart.com/uploads/1/3/0/8/130814581/502604.pdf
- http://files.sillassenhalf.com/uploads/1/3/0/9/130969555/bevijidu.pdf
- http://files.socialjusticemclc.org/uploads/1/3/2/7/132740338/6183263.pdf
- https://754744bd-3c9f-4a6a-8c2b-17534a016c4c.filesusr.com/ugd/145364_4816a3bf036d4058b9b133ff74009ad0.pdf?index=true
- https://0d0b0ca7-6f54-431f-aff3-f78dc2fb69b8.filesusr.com/ugd/dcc11b_e183284d869b4976b4b7b49d372bc732.pdf?index=true
- https://b728135d-b7a8-4510-bd72-1c46f206a0f7.filesusr.com/ugd/aef5b7_44f50a73972942e0bf95d2ba299bb786.pdf?index=true
- https://924a8f47-d855-4dd2-af8e-ef00be04c214.filesusr.com/ugd/fb5067_f4ba6d40f7b745c78b7974c00e93439d.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- ttraff.link
- a86a66e0-de0f-46b7-87a0-1e227422e571.filesusr.com
- a0265a74-d679-40c0-911f-4c7722f8432b.filesusr.com
- 050d644b-d873-49df-9a6d-d5088ff45ac6.filesusr.com
- 255f2204-478e-4d84-ad84-c15daad8613b.filesusr.com
- da514abc-7b9c-4886-bc8b-a479a601caa1.filesusr.com
- 12839eed-907b-4bf1-88ba-dd8ea023d9f5.filesusr.com
- files.samuelpakart.com
- files.sillassenhalf.com
- files.socialjusticemclc.org
- 754744bd-3c9f-4a6a-8c2b-17534a016c4c.filesusr.com
- 0d0b0ca7-6f54-431f-aff3-f78dc2fb69b8.filesusr.com
- b728135d-b7a8-4510-bd72-1c46f206a0f7.filesusr.com
- 924a8f47-d855-4dd2-af8e-ef00be04c214.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.123.252.220
- 92.223.78.30
- 20.165.94.46
- 135.232.92.137
- 40.99.133.226
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report