MALICIOUS — xisaworitil.pdf
MALICIOUS — xisaworitil.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Spam family. 2 of 50 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
408920e02ae5e682a0667b78551b52c39a68376131b1505f088b0b3a7d2d4e85 - SHA-1:
d2aa105fde59b3db81aeeb82a09248d61297c76a - MD5:
8f4139dccb618544d0f489cb6cebfdc2 - File type: pdf · Size: 46470 bytes
- Verdict: malicious (96/100) · Family: Spam
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Dynamic analysis (windows)
9678 behavior events · 1 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786524611&P2=404&P3=2&P4=CGmHhUuwH72DerCbNpgW9F001ecOPRcIb6VjFXx3WD%2ffh%2fl%2bDKPoz6UC0c0%2bTx22Q%2fkV6%2bpJbZWk3vUKOZWvMw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786524660&P2=404&P3=2&P4=lOjVvpwamkxb5Sk4vYDDI43FZvv2nN4ITnofdVwRW6Yb8QSJq9dfZHQntW3OlxgzYGv8BEppGGKgjly56frPOg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- 23.40.52.209
- 40.126.14.163
- 20.42.65.84 US · Flint Hill · AS8075 Microsoft Corporation
- 150.171.22.17
- 23.33.238.135
- 131.253.33.203
Dropped files
- /opt/CAPEv2/storage/analyses/12523/files/d84168d7a9cd83348dd8020e6dcebca21e2041cb638497935700a365d8a89587 —
d84168d7a9cd83348dd8020e6dcebca21e2041cb638497935700a365d8a89587 - /opt/CAPEv2/storage/analyses/12523/files/7f2abbef2000ebd4f3bd9352c2694d4930ed936cce329e477af335cf839da51e —
7f2abbef2000ebd4f3bd9352c2694d4930ed936cce329e477af335cf839da51e - root_.cache_dconf_user —
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.QP0A4NI7FC —
7925eb4d219d1155c5ce1fc3ce0818e4fec2ab00b7802f5caacab396f40685fd
Embedded URLs
- https://cctraff.ru/wb?keyword=technological%20innovations%20in%20education%20pdf
- https://bogadisosupotaj.weebly.com/uploads/1/3/0/7/130776541/kiwinawadana.pdf
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/piniwazikududi.pdf
- https://winomumamo.weebly.com/uploads/1/3/1/0/131070375/7787266.pdf
- https://uploads.strikinglycdn.com/files/30753676-8b8c-47b8-9962-19ffbbaa623c/33085668057.pdf
- https://uploads.strikinglycdn.com/files/102f2666-7f8f-4611-bd0c-b85aafaee947/273863967.pdf
- https://uploads.strikinglycdn.com/files/e4c19444-d522-4823-aa4c-1324c455430c/ad_aware_download.pdf
- https://uploads.strikinglycdn.com/files/33d7359d-19ea-4387-97f5-a5f32c88a6ba/79524156531.pdf
- https://s3.amazonaws.com/gupuso/acca_f1_practice_and_revision_kit.pdf
- https://s3.amazonaws.com/xanebavifamopez/12th_class_sociology.pdf
- https://s3.amazonaws.com/bupijila/la_quimica_del_cemento_portland.pdf
- https://s3.amazonaws.com/pazifetanegapu/cathode_ray_tube_working.pdf
- https://s3.amazonaws.com/sugaguxagu/fasejuwadebozifozotejew.pdf
- https://uploads.strikinglycdn.com/files/e5a898aa-0b6f-43b4-bbd7-451e968fed6b/nazenizori.pdf
- https://uploads.strikinglycdn.com/files/1f5ed8eb-71c0-4f0a-9781-188ebba974cd/sidulax.pdf
- https://uploads.strikinglycdn.com/files/36dbefa3-e983-4e50-b842-b38ea2f32713/larinonozetulaji.pdf
- https://uploads.strikinglycdn.com/files/09d0961d-2a8b-461a-b4fd-32837060527f/sapifevusa.pdf
- https://cdn.shopify.com/s/files/1/0495/9672/7460/files/96912940233.pdf
- https://cdn.shopify.com/s/files/1/0484/0217/0008/files/fevegedoliwopanofu.pdf
- https://cdn.shopify.com/s/files/1/0436/2056/5156/files/92822678958.pdf
- https://cdn.shopify.com/s/files/1/0492/2844/7900/files/philips_humidifier_2020_manual.pdf
- https://cdn.shopify.com/s/files/1/0484/4463/7352/files/5680948804.pdf
- https://cdn.shopify.com/s/files/1/0496/6540/9173/files/norton_anthology_of_english_literature.pdf
- https://cdn.shopify.com/s/files/1/0481/6322/5767/files/5657496784.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- bogadisosupotaj.weebly.com
- viweposedijul.weebly.com
- winomumamo.weebly.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 20.184.175.8
- 20.42.65.84
- 20.247.184.197
- 52.110.12.48
- 4.230.171.124
- 74.178.240.61
- 20.165.94.54
- 74.179.71.159
- 203.26.79.13
- 20.42.72.131
- 52.168.117.171
More Spam samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report