SUSPICIOUS — tabusulaf.pdf
SUSPICIOUS — tabusulaf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (68/100). 2 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
1fba898a44f93a94d163ab1595854b356792e6d6a845b30c4db12fbd6f430fa5 - SHA-1:
c5b9a76b4bebc1b7c3477610c6fb4186fa6a6827 - MD5:
f509ba8419fb3a6f2d719f6b8b2da41d - ssdeep:
768:agGzpDAKaAJ8SiiHghVfQTQCGTaOljU39f+cv9z6X9zCnOpMKZF/V7d:HGFEKy3ljU39fX9z6X9yOpxT/V7d - TLSH:
T1A5328CF750A3DD8C6A8F9B136DBA207A6049C788A127DB60449C732DC47C6ED7F60860 - Submitted as: tabusulaf.pdf
- File type: pdf · Size: 44002 bytes
- Verdict: suspicious (68/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 68/100 is the fusion of 6 weighted signals:
- Contacted 21 external host(s) at runtime (2 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=dramatic%20irony%20in%20oedipus%20rex%20pdf, https://cdn.shopify.com/s/files/1/0268/8391/5962/files/dumpster_apk_old_version_download.pdf, https://cdn.shopify.com/s/files/1/0491/7634/6790/files/the_prophet_kahlil_gibran_free_download.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9686 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- searchapp.bundleassets.example
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep._dosvc._tcp.local
- ntp.ubuntu.com
- desktop-hsgcbep(1)._dosvc._tcp.local
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\50d0af23267c0f6e3b7c63e7f6d980f4.png -
e8fd8ebda1560d779a9d5ccfc16dd3fff3f150aea75695ef2816c138d67f6112 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
aaccc212a13a8b5549b3a5db4a787425b09be6772e0d55aadf07ee369fb694ec - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://gettraff.ru/wb?keyword=dramatic%20irony%20in%20oedipus%20rex%20pdf
- https://cdn.shopify.com/s/files/1/0268/8391/5962/files/dumpster_apk_old_version_download.pdf
- https://cdn.shopify.com/s/files/1/0491/7634/6790/files/the_prophet_kahlil_gibran_free_download.pdf
- https://cdn.shopify.com/s/files/1/0440/5785/4102/files/41864368340.pdf
- https://cdn.shopify.com/s/files/1/0268/8247/4163/files/pabeso.pdf
- https://cdn.shopify.com/s/files/1/0483/2677/0852/files/types_of_axes.pdf
- https://s3.amazonaws.com/pazifetanegapu/93247185226.pdf
- https://s3.amazonaws.com/fatisake/pemowemuzovutesasib.pdf
- https://cdn-cms.f-static.net/uploads/4365541/normal_5f875be89e6fa.pdf
- https://cdn-cms.f-static.net/uploads/4374520/normal_5f8cc35350a15.pdf
- https://cdn-cms.f-static.net/uploads/4385647/normal_5f92f250ca480.pdf
- https://cdn-cms.f-static.net/uploads/4384026/normal_5f8ec4450b9bf.pdf
- https://uploads.strikinglycdn.com/files/cc35f500-6882-447e-bdd2-2edd12fd6ae4/shovel_knight_toader.pdf
- https://uploads.strikinglycdn.com/files/3b987f90-8ba4-493b-a8c4-26cba7b49273/goxisixotad.pdf
- https://uploads.strikinglycdn.com/files/9da0c106-ce9b-43eb-bc12-0d677878f0b2/76980448650.pdf
- https://uploads.strikinglycdn.com/files/5a2359b7-9674-46ea-b884-f589813858db/51925740032.pdf
- https://cdn-cms.f-static.net/uploads/4365575/normal_5f87e7d845840.pdf
- https://cdn-cms.f-static.net/uploads/4406170/normal_5f93271751b90.pdf
- https://cdn-cms.f-static.net/uploads/4374199/normal_5f8d1cbba8645.pdf
- https://cdn-cms.f-static.net/uploads/4383475/normal_5f936e6e52244.pdf
- https://uploads.strikinglycdn.com/files/cf48ada2-e1c6-44e4-b6d3-74e92cd938fb/1279046193.pdf
- https://uploads.strikinglycdn.com/files/73ea24b3-9f32-44ee-a9ba-646ad3e1831d/semizuguzalikogogonajo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 92.223.78.30
- 20.42.65.94
- 20.42.65.84
- 52.123.252.220
- 135.233.95.80
- 4.144.132.223
- 4.230.171.124
- 20.112.250.133
- 20.247.185.124
- 4.144.132.114
- 72.153.5.129
- 40.104.4.2
- 52.123.129.14
- 74.178.76.128
- 4.150.223.111
- 20.247.184.197
- 40.99.134.2
- 203.26.79.13
- 52.123.252.244
- 162.159.36.2
- 40.99.133.210
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report