SUSPICIOUS — normal_5f8b74d52ccf2.pdf
SUSPICIOUS — normal_5f8b74d52ccf2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (64/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0d7f53dea3917a2f04c542289aacc8acb4acd0f52752716bc0e8500dc7f4ead9 - SHA-1:
29b115595b9bd2e8e34e6764e17ce90e6e0547d5 - MD5:
67ac879ce046fec1640149f7cdd40afc - ssdeep:
768:egGzpDWeEnGhzBPrZNVd34nerwBi2p/G/s5hM9vCHy+3aLINrvW2SERTjTt0lq:bGFieHJvHIeUBiqVHh3aUN7WATt0lq - TLSH:
T1C3349EF310B7ED8C7ACAAB13A9AB2159544DC78C6236E760448C772CA1BC7FC6E10915 - Submitted as: normal_5f8b74d52ccf2.pdf
- File type: pdf · Size: 53406 bytes
- Verdict: suspicious (64/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 64/100 is the fusion of 5 weighted signals:
- Contacted 21 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://ttraff.ru/123?keyword=exists+movie+parents+guide, https://cdn-cms.f-static.net/uploads/4367005/normal_5f874e05c5981.pdf, https://cdn-cms.f-static.net/uploads/4369179/normal_5f8b6499193a4.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (15 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9817 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787773711&P2=404&P3=2&P4=hSdw7d0Zi9tyV90QOs%2f2PI%2f3a1Ns8k0hKt9HVWmPO0nt%2fr%2b1rs9XxzzYSABD0PcuyjRhcnlb%2fpUQ%2bqgugzMtTw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787773735&P2=404&P3=2&P4=OoixfEw2fqxIvMXkU9k21g5SnU92tMXfurSk3%2fQvC%2bSiE0XsOMTiG3DqcTaEZWoiu1bWvQs7DcahLNY6SEasuQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
9a224852b0bc2772cb55888043301d391d7ee20cfba79fd5224890fb138accf5 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\f36039ea8edca185297f806f931fa53f.png -
d82e0c8e7b53b5ca7cdf023f2668d7f4a6d6e205be98ac17f6ae8ac795e6ed31 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ttraff.ru/123?keyword=exists+movie+parents+guide
- https://cdn-cms.f-static.net/uploads/4367005/normal_5f874e05c5981.pdf
- https://cdn-cms.f-static.net/uploads/4369179/normal_5f8b6499193a4.pdf
- https://cdn-cms.f-static.net/uploads/4370052/normal_5f8b0773bdeeb.pdf
- https://cdn-cms.f-static.net/uploads/4368772/normal_5f8b7361c2635.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f86f4118e992.pdf
- https://xifobosakup.weebly.com/uploads/1/3/2/8/132815359/d4666c.pdf
- https://kinojapi.weebly.com/uploads/1/3/2/3/132302846/duzobitos.pdf
- https://cdn-cms.f-static.net/uploads/4381289/normal_5f8b689740a4d.pdf
- https://cdn-cms.f-static.net/uploads/4369663/normal_5f8862513e682.pdf
- https://cdn-cms.f-static.net/uploads/4370092/normal_5f89b58bec951.pdf
- https://cdn-cms.f-static.net/uploads/4378623/normal_5f8a059b0b6c3.pdf
- https://fakimodixoto.weebly.com/uploads/1/3/0/7/130739088/depebonunod-mukaxif-zipebotagamiv.pdf
- https://fakimodixoto.weebly.com/uploads/1/3/0/7/130739088/f559fcfbf9634ac.pdf
- https://wedebiki.weebly.com/uploads/1/3/0/9/130969436/b43669f2c.pdf
- https://uploads.strikinglycdn.com/files/c7ea2d1d-06ba-472c-90b2-40be6b65b48c/78650718165.pdf
- https://uploads.strikinglycdn.com/files/408e6d62-3e2f-483e-ad1c-66bbce96ff7c/92481403486.pdf
- https://uploads.strikinglycdn.com/files/5a55f5b0-7aea-432a-a8c7-1ee3351c9af3/22665010508.pdf
- https://uploads.strikinglycdn.com/files/c5023055-1ec1-44bf-8a9b-9c4e9cdada13/75916716674.pdf
- https://uploads.strikinglycdn.com/files/53c90955-96c0-418f-bce3-d71f00acacbe/62401111679.pdf
- https://cdn.shopify.com/s/files/1/0431/1764/1879/files/nixitesumitazagus.pdf
- https://cdn.shopify.com/s/files/1/0268/8217/9256/files/55232312628.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/lekefuxetupedin.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/kasaxegobezov.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ttraff.ru
- cdn-cms.f-static.net
- xifobosakup.weebly.com
- kinojapi.weebly.com
- fakimodixoto.weebly.com
- wedebiki.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 40.84.97.4
- 20.42.65.84
- 172.172.255.216
- 4.150.223.112
- 52.123.252.243
- 52.110.12.40
- 4.230.171.124
- 72.154.7.102
- 203.26.79.13
- 52.253.84.76
- 20.50.201.205
- 74.179.77.204
- 40.99.133.242
- 4.150.223.99
- 52.123.129.14
- 135.233.95.80
- 135.233.95.144
- 135.233.45.221
- 4.150.223.96
- 4.209.250.170
- 104.46.162.229
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report