SUSPICIOUS — normal_5f8749a7cb032.pdf
SUSPICIOUS — normal_5f8749a7cb032.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (64/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
2cda94725d784fbaa9c624fcc7f2a2f64a3527561cae27c6a975d139be30fb5d - SHA-1:
bab18a76e1017ffd406245ae1256861eeed5ec59 - MD5:
e80ca5752e9388328e387431e1b5aab4 - ssdeep:
1536:lGFkp+zkNm3LG5ppYVcNWgzdWGdGWEEOQO:4Fkp+zxbG5+cpwNR - TLSH:
T177339EF350A7ED4CBB8A9B477DEB1155608EC7886272DBA054882F2CC5BC5BD6E00D60 - Submitted as: normal_5f8749a7cb032.pdf
- File type: pdf · Size: 49434 bytes
- Verdict: suspicious (64/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 64/100 is the fusion of 5 weighted signals:
- Contacted 26 external host(s) at runtime (27 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/123?keyword=alone+piano+notes+pdf, https://site-1036750.mozfiles.com/files/1036750/sebuximovadapulapomu.pdf, https://site-1043538.mozfiles.com/files/1043538/47298719525.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
8710 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- config.edge.skype.com
- v20.events.data.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\bb14862d82548d00b6a9247ad2be12ce.png -
118aa3890d7e16c9e37fa6670754b32477c5228ac1b14f8ef67452e9daa793ae - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
4ad937c0f29759e88c069c3e8bb5389d5417e2a336fe3bf35885e0f8e86d4b6d
Embedded URLs
- https://gettraff.ru/123?keyword=alone+piano+notes+pdf
- https://site-1036750.mozfiles.com/files/1036750/sebuximovadapulapomu.pdf
- https://site-1043538.mozfiles.com/files/1043538/47298719525.pdf
- https://site-1037098.mozfiles.com/files/1037098/zupomevakoxerovimod.pdf
- https://site-1039149.mozfiles.com/files/1039149/vafas.pdf
- https://site-1039649.mozfiles.com/files/1039649/pitopizexolosebafuni.pdf
- https://cdn-cms.f-static.net/uploads/4367275/normal_5f87434857aea.pdf
- https://cdn-cms.f-static.net/uploads/4365621/normal_5f86f9d237dc9.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f86f4a44a669.pdf
- https://site-1043040.mozfiles.com/files/1043040/sewurosiluxumidoniwura.pdf
- https://site-1040683.mozfiles.com/files/1040683/77229885789.pdf
- https://site-1040888.mozfiles.com/files/1040888/65068875939.pdf
- https://site-1036629.mozfiles.com/files/1036629/gowalube.pdf
- https://site-1041489.mozfiles.com/files/1041489/23583740640.pdf
- https://site-1040876.mozfiles.com/files/1040876/ramaragiwijoxufojun.pdf
- https://site-1037149.mozfiles.com/files/1037149/17017885641.pdf
- https://site-1041591.mozfiles.com/files/1041591/bikebebegimexej.pdf
- https://site-1043810.mozfiles.com/files/1043810/17626462128.pdf
- https://uploads.strikinglycdn.com/files/741896a3-0606-425a-be76-29729edd74d0/75247130522.pdf
- https://uploads.strikinglycdn.com/files/b7760884-07ea-4e3b-96b9-daea831f7763/2644811806.pdf
- https://uploads.strikinglycdn.com/files/1589e444-2907-4c83-adb6-b32a10adf38a/kegotovarivipezezike.pdf
- https://uploads.strikinglycdn.com/files/f7cd0c85-a93e-484b-aaaa-c3a37e4edab3/26705341950.pdf
- https://uploads.strikinglycdn.com/files/453bfa9e-714c-44c7-94b7-b49f6e764b7e/dovadosugavarozobi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- site-1036750.mozfiles.com
- site-1043538.mozfiles.com
- site-1037098.mozfiles.com
- site-1039149.mozfiles.com
- site-1039649.mozfiles.com
- cdn-cms.f-static.net
- site-1043040.mozfiles.com
- site-1040683.mozfiles.com
- site-1040888.mozfiles.com
- site-1036629.mozfiles.com
- site-1041489.mozfiles.com
- site-1040876.mozfiles.com
- site-1037149.mozfiles.com
- site-1041591.mozfiles.com
- site-1043810.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.110.12.32
- 92.223.78.30
- 52.110.12.48
- 72.154.7.98
- 20.184.175.20
- 4.230.171.124
- 4.144.132.114
- 85.210.193.152
- 4.247.188.233
- 135.232.92.34
- 74.178.76.128
- 135.233.95.135
- 51.105.71.136
- 203.26.79.13
- 20.42.73.26
- 52.123.128.14
- 20.112.250.133
- 52.123.129.14
- 135.233.45.223
- 52.148.114.188
- 72.154.7.104
- 172.175.111.170
- 4.207.44.74
- 135.233.95.80
- 52.110.12.8
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report