MALICIOUS — 3835dd_1e9d89b074d74391b2c0ca174789e334.pdf
MALICIOUS — 3835dd_1e9d89b074d74391b2c0ca174789e334.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a38c127c6663846e3c4504593d14550b5a1f42f2b03f94c95f701ed1864c68c7 - SHA-1:
708710a126503b142bca21036b0ac68c3ab6f955 - MD5:
9ee80182d110d58cb427ec590871a26f - ssdeep:
768:AkgGzpDPSGrX9ZQRrygeac2xkY9uo+5T1wl+abtH9:ARGFb+c6kY9uoeT1q+abtH9 - TLSH:
T1B7308CF3449BED8D7A8B9303ADE70125108AD78A3137E760489C3B2CD47C6ADBE50960 - Submitted as: 3835dd_1e9d89b074d74391b2c0ca174789e334.pdf
- File type: pdf · Size: 37563 bytes
- Verdict: malicious (92/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 8 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:Trojan.PDF.SBadur.gen (rule
UDS:Trojan.PDF.SBadur.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 14 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.cc/wix?keyword=covalent+bonding+practice+problems+answers, https://cdn.shopify.com/s/files/1/0433/4744/3865/files/free_responsive_web_design_css_templates.pdf, https://cdn.shopify.com/s/files/1/0439/3353/2315/files/old_macdonald_had_a_farm_book_free.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (9 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1011 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- inference.location.live.net
- c.pki.goog
- to-do.office.com
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- staging.to-do.officeppe.com
- m365.cloud.microsoft
- ntp.ubuntu.com
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://www.msftconnecttest.com/connecttest.txt
- http://c.pki.goog/r/r1.crl
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ttraff.cc/wix?keyword=covalent+bonding+practice+problems+answers
- https://cdn.shopify.com/s/files/1/0433/4744/3865/files/free_responsive_web_design_css_templates.pdf
- https://cdn.shopify.com/s/files/1/0439/3353/2315/files/old_macdonald_had_a_farm_book_free.pdf
- https://cdn.shopify.com/s/files/1/0440/2351/3238/files/22134529961.pdf
- https://cdn.shopify.com/s/files/1/0434/2117/1864/files/janapada_geethalu_telugu_audio_songs.pdf
- https://cdn.shopify.com/s/files/1/0451/0469/3400/files/davis_industries_p_32.pdf
- https://cdn.shopify.com/s/files/1/0435/2642/2696/files/isaac_s_storm_discussion_questions_answers.pdf
- https://cdn.shopify.com/s/files/1/0431/9710/4288/files/3069973986.pdf
- https://cdn.shopify.com/s/files/1/0438/4948/2400/files/68045832579.pdf
- https://cdn.shopify.com/s/files/1/0431/8494/7357/files/delove.pdf
- https://cdn.shopify.com/s/files/1/0462/9538/4225/files/worarujefinokegemupeb.pdf
- https://3d1a92a9-3bb1-4326-9dd6-79a1e845264b.filesusr.com/ugd/5bb01c_4214db3df3aa4b92958d948d230aff9c.pdf?index=true
- https://fcb6dd8a-3914-4aaf-b706-dee4fc1c8008.filesusr.com/ugd/c79b1c_576b9083c5c54bed92768394aaa268bb.pdf?index=true
- https://db7b97ba-2309-4daa-941b-7c7363180c8b.filesusr.com/ugd/e643da_8e27b0bee3364dc58b7721229f8689f3.pdf?index=true
- https://437a6c8b-497e-4725-aa4f-93f487df9d87.filesusr.com/ugd/69695d_cc62cd1a8c9e412ba61b8cf234055d95.pdf?index=true
- https://f71f3868-3262-4c18-a8ad-8bd92578d285.filesusr.com/ugd/1cc777_c4ad4bd21628473bbfb8770bea30b195.pdf?index=true
- https://5d2398bb-fd4b-421e-ab12-9261cd106200.filesusr.com/ugd/1cc777_8ed11c754c6d430288b7ca11fb4d484e.pdf?index=true
- https://129abf06-63b3-41ba-ba61-28caa18a9c4a.filesusr.com/ugd/696117_2af62de447764666bcf7f0da8723d5db.pdf?index=true
- https://7db8132b-26c4-462b-ab2a-c15598376ec5.filesusr.com/ugd/a4ea6c_b4d2468ed8534d09b9faa1425baa9653.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.cc
- cdn.shopify.com
- 3d1a92a9-3bb1-4326-9dd6-79a1e845264b.filesusr.com
- fcb6dd8a-3914-4aaf-b706-dee4fc1c8008.filesusr.com
- db7b97ba-2309-4daa-941b-7c7363180c8b.filesusr.com
- 437a6c8b-497e-4725-aa4f-93f487df9d87.filesusr.com
- f71f3868-3262-4c18-a8ad-8bd92578d285.filesusr.com
- 5d2398bb-fd4b-421e-ab12-9261cd106200.filesusr.com
- 129abf06-63b3-41ba-ba61-28caa18a9c4a.filesusr.com
- 7db8132b-26c4-462b-ab2a-c15598376ec5.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 52.110.12.42
- 172.64.154.167
- 52.123.129.14
- 74.178.240.61
- 74.178.76.54
- 20.50.201.201
- 57.154.63.210
- 4.230.171.124
- 20.184.175.15
- 4.150.223.98
- 20.165.94.63
- 162.159.36.2
- 23.103.236.44
- 23.103.236.3
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report