MALICIOUS — bdb868.pdf
MALICIOUS — bdb868.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 2 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
5bceb92d7e71bf3ff4178e60734bbef716c59bb254c328675636f568a80f1044 - SHA-1:
7a20abf7ef132c76ad4de5ed63c0cdc888f1d006 - MD5:
7aac796cf155907bc1d758e33be3c63e - File type: pdf · Size: 55770 bytes
- Verdict: malicious (96/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Dynamic analysis (windows)
9876 behavior events · 1 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786522670&P2=404&P3=2&P4=J2YOLw5VZJIHyqgnQYvJfnluqfYpc4fRG5etSGP2uaSyQXYDad8AhEzh0MvcwUCXsGcluTwBSRLx9hVs5k%2bA%2fg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786522703&P2=404&P3=2&P4=Gz%2fnB5CqLoMYDBN7AkWUWu6r0uTMULi7bIUgm%2b2lXmEmtmnJ90TdzW12ThPkPkr1QRSFd6g4otO6AD0L72h2Dg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- 23.40.52.85
- 20.190.167.149
- 20.42.65.85 US · Flint Hill · AS8075 Microsoft Corporation
- 20.247.184.197 SG · Singapore · AS8075 Microsoft Corporation
- 23.33.238.178
- 23.198.40.44
Dropped files
- /opt/CAPEv2/storage/analyses/12454/files/720706f3d147ef7e0cca5200e69204c761b176ef632faddf16161dee297db0b3 —
720706f3d147ef7e0cca5200e69204c761b176ef632faddf16161dee297db0b3 - /opt/CAPEv2/storage/analyses/12454/files/9151c891a98b6c23e20ad9b4e5ef3ef45a13ce3be8981ac3f27b442a7837921c —
9151c891a98b6c23e20ad9b4e5ef3ef45a13ce3be8981ac3f27b442a7837921c - root_.cache_dconf_user —
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.y3EPKDB8Eh —
62b70052cd8f70b00b49cbf9cf62079a63f1627282632fa6696101c8d80b08d7
Embedded URLs
- https://ggtraff.ru/wb?keyword=kanai%20cube%20diablo%203
- https://site-1043200.mozfiles.com/files/1043200/49201442208.pdf
- https://site-1043608.mozfiles.com/files/1043608/rojapajaxuw.pdf
- https://site-1043403.mozfiles.com/files/1043403/77548650304.pdf
- https://site-1040178.mozfiles.com/files/1040178/34424758583.pdf
- https://cdn.shopify.com/s/files/1/0439/3009/1688/files/knowledge_is_beautiful_download.pdf
- https://cdn.shopify.com/s/files/1/0486/2210/8837/files/my_site_speed_google.pdf
- https://cdn.shopify.com/s/files/1/0266/8409/6700/files/kite_fighting_string.pdf
- https://cdn.shopify.com/s/files/1/0481/6617/4871/files/jewellery_drawing_techniques.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/wegedarekon_zixaluwifaxuves_muwobefakufixi_gitogezumi.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/zuvefusu_tewojawowebav.pdf
- https://jedunaxalow.weebly.com/uploads/1/3/1/6/131606453/5365052.pdf
- https://fekudumubaf.weebly.com/uploads/1/3/2/6/132681201/bodajetosason-bipejugibelumar-dupatiror-zabupuzuta.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/ce02014a20d.pdf
- https://vevejeda.weebly.com/uploads/1/3/0/7/130776099/gomesepopudikapesozi.pdf
- https://cdn-cms.f-static.net/uploads/4366357/normal_5f87ee9752a98.pdf
- https://cdn-cms.f-static.net/uploads/4366978/normal_5f884ff6aa198.pdf
- https://cdn-cms.f-static.net/uploads/4365649/normal_5f871bcc7c674.pdf
- https://cdn-cms.f-static.net/uploads/4367947/normal_5f8790cbd6cab.pdf
- https://cdn-cms.f-static.net/uploads/4367312/normal_5f87b151c3898.pdf
- https://site-1040521.mozfiles.com/files/1040521/16800910336.pdf
- https://site-1041587.mozfiles.com/files/1041587/60722868557.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- site-1043200.mozfiles.com
- site-1043608.mozfiles.com
- site-1043403.mozfiles.com
- site-1040178.mozfiles.com
- cdn.shopify.com
- nudojafobedem.weebly.com
- jawasolasazilem.weebly.com
- jedunaxalow.weebly.com
- fekudumubaf.weebly.com
- bedizegoresupa.weebly.com
- vevejeda.weebly.com
- cdn-cms.f-static.net
- site-1040521.mozfiles.com
- site-1041587.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 135.232.92.137
- 20.42.65.85
- 20.247.184.197
- 52.110.12.33
- 4.230.171.124
- 74.178.76.44
- 72.154.7.106
- 203.26.79.13
- 74.178.76.128
- 20.50.201.204
- 92.223.78.30
- 74.178.240.61
- 20.184.175.23
- 13.69.116.104
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report