SUSPICIOUS — 8905105.pdf
SUSPICIOUS — 8905105.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (56/100). 2 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
1d3abd482cf81c8a632389ccce8675154e8be1ea1f126c66576435d16b949ff6 - SHA-1:
019813e1a11884a076a756e53634200eb516c071 - MD5:
f69925c82dc6607284df3f3f6d6b9d42 - ssdeep:
768:3gGzpDEeJgeXFmXvr4VMG+2ocUqDxE33xmsur8OzpJAY4YLWEwBBeLN8kWt8lmTn:QGFQeJnT/JA8LWZBYukU8lSgDTu - TLSH:
T13A34AFF310A7DE8D7BCBAB4368BA0155A08AD7897122A6904588BB3CC07C5FD7F11A51 - Submitted as: 8905105.pdf
- File type: pdf · Size: 55998 bytes
- Verdict: suspicious (56/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 56/100 is the fusion of 6 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=alebrijes%20de%20oaxaca%20artesanias, https://cdn.shopify.com/s/files/1/0439/3389/2763/files/amazing_grace_notes_with_letters.pdf, https://cdn.shopify.com/s/files/1/0500/9198/3013/files/bidufuvanezedivala.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 8 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9627 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- searchapp.bundleassets.example
- inference.location.live.net
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep
- desktop-hsgcbep._dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
- 20.190.167.149
- 20.190.167.150
- 23.33.238.112
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
147705f54f89174c8a28cdaf5c25ba4665a66e7d0adfb18a7f6cd08b6123f7b6 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\c5a80e8f751fd215644076ea31ce489e.png -
337b47118b6bc6dd8d82b43d84311199c3a789872f117c173e9b146e9786c202 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://gettraff.ru/wb?keyword=alebrijes%20de%20oaxaca%20artesanias
- https://cdn.shopify.com/s/files/1/0439/3389/2763/files/amazing_grace_notes_with_letters.pdf
- https://cdn.shopify.com/s/files/1/0500/9198/3013/files/bidufuvanezedivala.pdf
- https://cdn.shopify.com/s/files/1/0429/2693/2124/files/golds_gym_elliptical_350i_manual.pdf
- https://cdn.shopify.com/s/files/1/0488/4080/2469/files/manigaxilibexera.pdf
- https://cdn.shopify.com/s/files/1/0431/8098/2438/files/convert_exe_to_apk_software_online.pdf
- https://cdn-cms.f-static.net/uploads/4373016/normal_5f88d4526d8f9.pdf
- https://cdn-cms.f-static.net/uploads/4366010/normal_5f87180b92cb5.pdf
- https://cdn-cms.f-static.net/uploads/4369760/normal_5f8ccf6aaee23.pdf
- https://cdn-cms.f-static.net/uploads/4378381/normal_5f8cb096d40ff.pdf
- https://cdn.shopify.com/s/files/1/0499/8902/5942/files/do_all_unicorns_have_wings.pdf
- https://cdn.shopify.com/s/files/1/0429/7100/5082/files/19842805920.pdf
- https://cdn.shopify.com/s/files/1/0436/4386/3198/files/aspen_x2_portland.pdf
- https://cdn.shopify.com/s/files/1/0433/6012/5080/files/69967642528.pdf
- https://uploads.strikinglycdn.com/files/19ebcf77-eaa2-4561-8663-912e64363bd8/paxaxav.pdf
- https://uploads.strikinglycdn.com/files/5c9d955e-3899-4292-90aa-e7eacc7ff328/jivitusisoravuxokarifubad.pdf
- https://cdn-cms.f-static.net/uploads/4376600/normal_5f8babe8c3a66.pdf
- https://cdn-cms.f-static.net/uploads/4366354/normal_5f8783602cf79.pdf
- https://cdn-cms.f-static.net/uploads/4366024/normal_5f870ed24ff13.pdf
- https://cdn-cms.f-static.net/uploads/4365601/normal_5f874ea269986.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 92.223.78.30
- 52.110.12.45
- 135.234.160.245
- 40.79.141.152
- 52.123.252.216
- 4.230.171.124
- 20.42.179.192
- 162.159.36.2
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report