MALICIOUS — 76c30d49.pdf
MALICIOUS — 76c30d49.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Spam family. 2 of 50 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
5dc7ff6bd7fc3a433aec47839a8426dae0455e57ced28fbb300fb3e973e9c28b - SHA-1:
aa8cc3a49ff666a58b49848d6eb93093abe638aa - MD5:
eda7c0e88aebcf14516c1d8501fa06b0 - File type: pdf · Size: 68629 bytes
- Verdict: malicious (98/100) · Family: Spam
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Dynamic analysis (windows)
9788 behavior events · 1 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786524693&P2=404&P3=2&P4=FbGPFiow7AXHfcJf6tCb7ubv5IxrxzD2zsh1gofdZdXhXbFnE7LWP1HAjZsbMoYr0w7q%2fGr%2fgZkhNtPLnGSv6w%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786524749&P2=404&P3=2&P4=kW7jztVqnwsCGtPCH2tTRFgOnNRgvt5DKmkzdtTBltA70liVeuvi2Z4Q8s%2f0UWWSlxQvflupKe6u3ylZoYh4Zg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- 23.40.52.85
- 20.190.167.20
- 52.123.252.198 AU · Sydney · AS8075 Microsoft Corporation
- 23.11.37.157
- 85.210.193.152 GB · AS8075 MICROSOFT-MAINT
- 52.110.12.18 AU · Sydney · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
Dropped files
- /opt/CAPEv2/storage/analyses/12525/files/a05e8e9084e1533efd1a91c41a19d3b09328b987fab5002551a2bde5208eba8d —
a05e8e9084e1533efd1a91c41a19d3b09328b987fab5002551a2bde5208eba8d - /opt/CAPEv2/storage/analyses/12525/files/01151e9b56866d672452596eb82a5b0e5bdb72b706fad83f499c0e393a5c4c62 —
01151e9b56866d672452596eb82a5b0e5bdb72b706fad83f499c0e393a5c4c62 - root_.cache_dconf_user —
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.JRRU4Lac8L —
81005cf396c5b3ad6e07bdc0c44cd8b531c3b9e603421bcd6e44a54895018fa0
Embedded URLs
- https://ggtraff.ru/wb?keyword=advanced%20engineering%20mathematics%20by
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/xekena.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/zuvefusu_tewojawowebav.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/wozumadaku-mukevewurovebu-nefebo.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/sokilijaw.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/8279107.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/belapigojat.pdf
- https://uploads.strikinglycdn.com/files/c9551188-b076-4752-9cb9-73f7330e3c44/17242249211.pdf
- https://uploads.strikinglycdn.com/files/9b5890f5-32c6-4f37-ad2c-2a9ad18f9634/6069380852.pdf
- https://uploads.strikinglycdn.com/files/d084ab37-09c1-4aca-a0d5-6a60e450c401/87771651966.pdf
- https://uploads.strikinglycdn.com/files/4e2ad4e3-e1f6-4ece-b8f0-3856e2f6e2f5/likosi.pdf
- https://uploads.strikinglycdn.com/files/7bd70d06-9e02-4b1a-b2a0-15e47c339c10/rubotewuvebezunazu.pdf
- https://uploads.strikinglycdn.com/files/43428291-a4b2-4e36-b8ec-205130c0f106/zosara.pdf
- https://uploads.strikinglycdn.com/files/898f38cc-895c-4c13-901a-6163fa6a6a5e/mikitanikezumawux.pdf
- https://uploads.strikinglycdn.com/files/904f6d88-34c6-49d2-95d1-461f3f5e87fb/sororilutovapupizonupos.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786524693&P2=404&P3=2&P4=FbGPFiow7AXHfcJf6tCb7ubv5IxrxzD2zsh1gofdZdXhXbFnE7LWP1HAjZsbMoYr0w7q%2fGr%2fgZkhNtPLnGSv6w%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Embedded domains
- ggtraff.ru
- xojerajap.weebly.com
- jawasolasazilem.weebly.com
- jakedekokobara.weebly.com
- keniwuki.weebly.com
- fijojonibiw.weebly.com
- guwomenod.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 74.178.240.61
- 4.150.223.112
- 52.123.252.198
- 85.210.193.152
- 52.110.12.18
- 4.230.171.124
- 52.253.84.76
- 203.26.79.13
- 52.123.252.240
- 52.178.17.235
- 135.233.45.222
- 74.179.71.159
- 4.209.250.170
- 172.217.25.163
More Spam samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report