SUSPICIOUS — 95047794945.pdf
SUSPICIOUS — 95047794945.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (64/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1d8e882119ed3a751ff49066f3a78618875b3e1c87df4f1508f4f49ee9d62c7c - SHA-1:
25093a49aed8a4224bf3e163f597d70cce44e477 - MD5:
6c8d25ce9dc9848e7b100801aa8f8587 - ssdeep:
1536:kGFePDrCwLOtjd+GNkBDEa2Gn29PC79K8us:xFeLrCwS7+uaEa7P9J - TLSH:
T1DA33B0F341ABEDCC2E86AB17A8B6056D548AC38C6131E76454C87B2CD0BC2FEBE50511 - Submitted as: 95047794945.pdf
- File type: pdf · Size: 52080 bytes
- Verdict: suspicious (64/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 64/100 is the fusion of 5 weighted signals:
- Contacted 16 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=urinary+catheterization+procedure+male+pdf, https://uploads.strikinglycdn.com/files/5515e973-fc00-459a-84c4-8e574a9f16a1/jiwisugabinopowaj.pdf, https://uploads.strikinglycdn.com/files/e9087e01-3884-45d1-abd0-f5ced7d50154/wiliduvorokuvexifeg.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (17 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9792 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787781246&P2=404&P3=2&P4=JMCI3qUuue2fZas9v7hHkc0lwgWb%2fKvF8IKs%2f9gjV8LN39XqFMWESgZJJUbWbAqZxd2LkCjyKzfAnb78GI6DnA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787781302&P2=404&P3=2&P4=G%2fPtpx2dnzJ9h0K7Pav50rGzSxYr2Rfx4RUWolQayLCWKFSv%2bMSEOO9QPn18496AyOdwilh3Dtv24wOojP42tQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787177962&P2=404&P3=2&P4=ccSxSSAHrh1qgBq91bzrMWiQlJnp46EXCKj%2bW%2bOpb1NCfUbl%2feWDjtQkLLtpsBPrsyx3y0zsf3g9%2fzb00%2flkJg%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\fd10964543f0163c6bf0405fecfc4474.png -
f99930465c3c3347b7333cd2839bc75561afe21d826ceae9a398aa2c3d0dc8f7 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
d1b5fa0b8419996174efa1dc657d94f9722438360902e9452fe3948496c80823 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://gettraff.ru/strik?keyword=urinary+catheterization+procedure+male+pdf
- https://uploads.strikinglycdn.com/files/5515e973-fc00-459a-84c4-8e574a9f16a1/jiwisugabinopowaj.pdf
- https://uploads.strikinglycdn.com/files/e9087e01-3884-45d1-abd0-f5ced7d50154/wiliduvorokuvexifeg.pdf
- https://uploads.strikinglycdn.com/files/a0fb49df-f486-442b-aadf-e4bdbdb1c5a7/momiged.pdf
- https://uploads.strikinglycdn.com/files/41980033-0318-4b2a-954a-b6cd5809eb85/7042872094.pdf
- http://files.our-simple-life.com/uploads/1/3/1/1/131164023/a3429fa.pdf
- http://files.reliefequineproducts.com/uploads/1/3/2/3/132303133/3443880.pdf
- http://files.footlightstheater.com/uploads/1/3/0/8/130813948/ed103.pdf
- http://files.palmsdrycleaning.com/uploads/1/3/1/0/131070872/6af44ee5.pdf
- http://files.unlockedgolf.com/uploads/1/3/0/7/130739285/vosefafiniraxigopeva.pdf
- http://kudutel.vintagewoodworkingtools.net/uploads/1/3/1/1/131164424/2777095.pdf
- http://fetaf.greenmountaintreats.com/uploads/1/3/1/8/131856235/c6949603f660.pdf
- http://files.cmcfn.com/uploads/1/3/1/3/131383407/3072510.pdf
- https://site-1037106.mozfiles.com/files/1037106/31249645589.pdf
- https://site-1036867.mozfiles.com/files/1036867/wobixalowijudekaz.pdf
- https://site-1037130.mozfiles.com/files/1037130/77926162221.pdf
- https://site-1036750.mozfiles.com/files/1036750/pasajuxinesulag.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- files.our-simple-life.com
- files.reliefequineproducts.com
- files.footlightstheater.com
- files.palmsdrycleaning.com
- files.unlockedgolf.com
- kudutel.vintagewoodworkingtools.net
- fetaf.greenmountaintreats.com
- files.cmcfn.com
- site-1037106.mozfiles.com
- site-1036867.mozfiles.com
- site-1037130.mozfiles.com
- site-1036750.mozfiles.com
- www.heart.org
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 92.223.78.30
- 4.150.223.107
- 52.123.252.230
- 57.154.63.210
- 4.230.171.124
- 52.230.59.222
- 20.165.94.63
- 51.132.193.105
- 20.76.201.171
- 52.123.128.14
- 203.26.79.13
- 52.123.252.242
- 135.233.95.80
- 135.233.45.223
- 48.200.63.27
- 4.150.223.113
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report