MALICIOUS — belapigojat.pdf
MALICIOUS — belapigojat.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 2 of 50 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
2a4e76438170558c3f1cfc8ef70630ca21c40615e5fe97749dbb94ff08f4275a - SHA-1:
2ffb4aa4bf594186d516bd51c08aedeb924f80bc - MD5:
ceb3e2ab20a736e0b8fed3c30caf1c37 - File type: pdf · Size: 45706 bytes
- Verdict: malicious (98/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Dynamic analysis (windows)
9762 behavior events · 1 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- c.pki.goog
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786525656&P2=404&P3=2&P4=Ffc4j%2fN2FE55L0m1%2fdzmEsKZdEo73VFPcpqm5GmVyY%2fEBc3wIVTWOhAC28yNWYpjoaSXL%2f8hflKHe8kXpMwGEQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786525690&P2=404&P3=2&P4=RF5J8%2bsVaU27WUG9rztfPwVwBZ0Dth4nZaeCzFhYbTX%2fg6ew7fEDYz7VKnDNzmt0rKetjtJ29HfNyPcELIB81A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://c.pki.goog/r/gsr1.crl
- http://c.pki.goog/r/r4.crl
- http://c.pki.goog/we1/_-4iFwfCacM.crl
- 23.40.52.209
- 40.126.14.164
Dropped files
- /opt/CAPEv2/storage/analyses/12560/files/1060863bf29cdd1accee2349f7cacb5a47ddde52e3788036f0c6b9860c87d27f —
1060863bf29cdd1accee2349f7cacb5a47ddde52e3788036f0c6b9860c87d27f - /opt/CAPEv2/storage/analyses/12560/files/a386faac583b9a977630cce8783384535247c0368ea5d4a633c919f724417e46 —
a386faac583b9a977630cce8783384535247c0368ea5d4a633c919f724417e46 - root_.cache_dconf_user —
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.M0EsMVB5rc —
c6fb620d5f09e679574541a7e46b13ed8fdbdbf4e615818e4be9c762149bb1b5
Embedded URLs
- https://gettraff.ru/wb?keyword=xps%208930%20review
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/kezedivalo-bolumukejufufik.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/ce02014a20d.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/laresisif_kigadebokenub_bajutinerid.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/0c18874847f.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/bewoti.pdf
- https://jemiwuwavaza.weebly.com/uploads/1/3/0/8/130814288/tigosorivibisakoxu.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/tifuxasorelav-sunagutigu-gikisifexixabot.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/dekegu.pdf
- https://cdn.shopify.com/s/files/1/0429/5360/5273/files/eviction_defense_manual.pdf
- https://cdn.shopify.com/s/files/1/0501/1682/1157/files/63004363703.pdf
- https://uploads.strikinglycdn.com/files/d1099f9e-1e6e-4d7e-8282-8802be299220/62043598971.pdf
- https://uploads.strikinglycdn.com/files/a3ac8300-b749-4379-bb95-45ae7011a4d8/xijuzibok.pdf
- https://uploads.strikinglycdn.com/files/8d30716d-a4f4-40f4-8f10-bb8c16e40015/17705665716.pdf
- https://uploads.strikinglycdn.com/files/c7ecafaa-80eb-4b5e-9533-b44d4f43975c/93677611217.pdf
- https://uploads.strikinglycdn.com/files/cd927583-3dfa-4530-997b-8d78670e2f11/xotarenijazo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786525656&P2=404&P3=2&P4=Ffc4j%2fN2FE55L0m1%2fdzmEsKZdEo73VFPcpqm5GmVyY%2fEBc3wIVTWOhAC28yNWYpjoaSXL%2f8hflKHe8kXpMwGEQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- gettraff.ru
- dimaxafazeza.weebly.com
- bedizegoresupa.weebly.com
- genigudepa.weebly.com
- dutitujazekap.weebly.com
- vuxozajuje.weebly.com
- jemiwuwavaza.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 74.179.77.204
- 20.184.175.17
- 74.179.71.159
- 52.110.12.52
- 57.155.101.212
- 72.154.7.107
- 4.230.171.124
- 203.26.79.13
- 135.232.92.97
- 4.150.223.102
- 135.232.92.137
- 4.150.223.108
- 92.223.78.30
- 142.250.195.163
- 172.175.111.170
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report