MALICIOUS — zonatuxafij.pdf
MALICIOUS — zonatuxafij.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 5 of 50 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
2c6cbf2761979ab664e6719724a4cf8c250aa1443bb976464577478ff8504991 - SHA-1:
860431872818a176030c518b7b6bbc44189ed78b - MD5:
7f762d7a6b3f18effc9e2d01b0d5d16b - File type: pdf · Size: 87131 bytes
- Verdict: malicious (99/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!7F762D7A6B3F
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Dynamic analysis (windows)
9708 behavior events · 1 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- 250.255.255.239.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786511929&P2=404&P3=2&P4=KZ0yeFOq02xqG78ddHDysAw%2fRtvvJUA01MCtK%2fnYQgY59wJwxhKjG7Tjw63%2fjPuG9STzTKx4HlsBlV3XW1mcBg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786511959&P2=404&P3=2&P4=SFapk22MLdT%2b4gCdEvohe6VlzuIwXFz3qMkkjVsDY7eFITdKpdvcAv7uu0hBm3K2Jp2eEqXTydPA1HMxz8ojCg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- 23.40.52.209
- 192.168.122.115
- 40.126.14.163
- 40.79.163.155 AU · Sydney · AS8075 Microsoft Corporation
- 23.11.37.157
- 23.198.40.44
Dropped files
- /opt/CAPEv2/storage/analyses/12122/files/667069b010c612678bbdd988a71b0a205795e91a52f39ee8fa5fadf1eec8572d —
667069b010c612678bbdd988a71b0a205795e91a52f39ee8fa5fadf1eec8572d - /opt/CAPEv2/storage/analyses/12122/files/77ba46746696932cf219e7bb23da7ad65c1827f4cf2e64832c02f7410f029d1b —
77ba46746696932cf219e7bb23da7ad65c1827f4cf2e64832c02f7410f029d1b - root_.cache_dconf_user —
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.ac5JEzy2Ww —
91389620a0e4a79729b87444bf8be62d34fb9a06a5b470199a4122fae3ec9c64
Embedded URLs
- https://cctraff.ru/wb?keyword=pixel%20royale%20gun%203d%20mobile%20unknown%20battle%20ground
- https://cdn-cms.f-static.net/uploads/4366010/normal_5f8887b7f362d.pdf
- https://site-1178342.mozfiles.com/files/1178342/christ_church_hospital_school_uniform.pdf
- https://site-1177566.mozfiles.com/files/1177566/80s_hit_list_youtube.pdf
- https://static.s123-cdn-static.com/uploads/4378153/normal_6006d32c5a87d.pdf
- https://cdn-cms.f-static.net/uploads/4414176/normal_5fbeaf31393fa.pdf
- https://static.s123-cdn-static.com/uploads/4471686/normal_6002634664ef7.pdf
- http://lozisuvuxinosog.epizy.com/osrs_0-_99_crafting_guide.pdf
- https://cdn-cms.f-static.net/uploads/4454544/normal_5fd77da5011b1.pdf
- https://cdn.sqhk.co/vimexuda/chbW4to/daniel_and_regina_call_video_2020.pdf
- https://site-1168233.mozfiles.com/files/1168233/garetowet.pdf
- https://cdn-cms.f-static.net/uploads/4372100/normal_5f9e3d75b1c55.pdf
- https://site-1166064.mozfiles.com/files/1166064/brock_s_performance_clutch_mod.pdf
- https://static.s123-cdn-static.com/uploads/4376598/normal_5feec6939e5ca.pdf
- https://static.s123-cdn-static.com/uploads/4492294/normal_6007e78f98806.pdf
- https://cdn-cms.f-static.net/uploads/4382778/normal_5fa86a71dc10d.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786511929&P2=404&P3=2&P4=KZ0yeFOq02xqG78ddHDysAw%2fRtvvJUA01MCtK%2fnYQgY59wJwxhKjG7Tjw63%2fjPuG9STzTKx4HlsBlV3XW1mcBg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- site-1178342.mozfiles.com
- site-1177566.mozfiles.com
- static.s123-cdn-static.com
- lozisuvuxinosog.epizy.com
- cdn.sqhk.co
- site-1168233.mozfiles.com
- site-1166064.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 135.233.95.144
- 40.79.163.155
- 52.110.12.15
- 52.110.12.1
- 4.230.171.124
- 40.84.97.4
- 74.178.76.128
- 20.184.175.18
- 20.184.175.21
- 172.178.240.162
- 74.179.71.159
- 203.26.79.13
- 52.123.252.227
- 4.150.223.101
- 172.178.240.161
- 4.150.223.108
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report