SUSPICIOUS — normal_5f88c42d30c63.pdf
SUSPICIOUS — normal_5f88c42d30c63.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (64/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
30d992e772b118d08bbaf13849ecbf126b0b4f20bafd408988a7e9c8e8aa62c8 - SHA-1:
6e01b60816ed7c6deb46b2600dd352a64bdff223 - MD5:
b65b727dd1b225e5ed3161172fd6cea1 - ssdeep:
768:ogGzpDdeRSBxGJaDY3eNkuSOE6GV1Krg2fjpYUnj+SYN7elTWkgFAe2:lGF5eRpwSOE6igYxS27eo3FN2 - TLSH:
T18A338DF354E7ED8C7A87A703A9EA1065608AC78C6233DBA1448C772DD5BC1BD7E10921 - Submitted as: normal_5f88c42d30c63.pdf
- File type: pdf · Size: 47767 bytes
- Verdict: suspicious (64/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 64/100 is the fusion of 5 weighted signals:
- Contacted 25 external host(s) at runtime (26 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/123?keyword=animal+crossing+city+folk+shoe+shine+guide, https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/serovula.pdf, https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/vanesasiwe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (9 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
8694 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\ef36dad7c8dabedc2b46801cfea0e70c.png -
989abfed8ce534f274a673c630d3d93fe0983020453feda9bfa5823793891e18 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
a179c09d27b98da15efe8bb75e85d09827d4fecd5d396c98e47dcae6dc515b3f
Embedded URLs
- https://gettraff.ru/123?keyword=animal+crossing+city+folk+shoe+shine+guide
- https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/serovula.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/vanesasiwe.pdf
- https://pevugubak.weebly.com/uploads/1/3/2/7/132740457/8502473.pdf
- https://gurigibafex.weebly.com/uploads/1/3/0/7/130739571/rumalax-gixasufusez-labunajigom-popado.pdf
- https://cdn.shopify.com/s/files/1/0437/0792/4635/files/78965808293.pdf
- https://cdn.shopify.com/s/files/1/0431/5663/5816/files/5e_druid_spell_focus.pdf
- https://cdn.shopify.com/s/files/1/0428/5811/9334/files/witanomekenemudegigato.pdf
- https://cdn.shopify.com/s/files/1/0431/9100/9442/files/5398041060.pdf
- https://cdn.shopify.com/s/files/1/0501/0240/3237/files/miracle_whip_qrp_antenna.pdf
- https://uploads.strikinglycdn.com/files/2079872a-860a-458b-bfcc-e47c181a0275/7082166728.pdf
- https://uploads.strikinglycdn.com/files/79d20f11-9f8a-4a25-9bc3-ea2525d033bf/88797426594.pdf
- https://uploads.strikinglycdn.com/files/b98d4381-de0a-44e9-aa99-e52f3c7f19df/81280935973.pdf
- https://uploads.strikinglycdn.com/files/23cb073c-78f9-4c3b-8536-d89cd625d005/12764348323.pdf
- https://uploads.strikinglycdn.com/files/8f4ab026-7f1c-4b20-bf64-90045c7bbba5/konul.pdf
- https://site-1041501.mozfiles.com/files/1041501/91400563830.pdf
- https://site-1048474.mozfiles.com/files/1048474/81145410692.pdf
- https://site-1037180.mozfiles.com/files/1037180/wekoje.pdf
- https://tidoxanarapora.weebly.com/uploads/1/3/2/7/132710787/sabilutesekobalusibe.pdf
- https://gexirirexov.weebly.com/uploads/1/3/0/8/130874239/tijuwerabis.pdf
- https://dokodajibebabek.weebly.com/uploads/1/3/2/3/132302773/tajugagu-lanaw-sidupu-solavepo.pdf
- https://narogigadi.weebly.com/uploads/1/3/0/8/130874066/c2099e721b.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/xekena.pdf
- https://cdn.shopify.com/s/files/1/0434/4230/7233/files/nagurimovoju.pdf
- https://cdn.shopify.com/s/files/1/0434/0364/0993/files/49641181621.pdf
Embedded domains
- gettraff.ru
- tivakoxidedopa.weebly.com
- jaserasozupog.weebly.com
- pevugubak.weebly.com
- gurigibafex.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1041501.mozfiles.com
- site-1048474.mozfiles.com
- site-1037180.mozfiles.com
- tidoxanarapora.weebly.com
- gexirirexov.weebly.com
- dokodajibebabek.weebly.com
- narogigadi.weebly.com
- xojerajap.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 51.11.192.48
- 52.123.252.198
- 4.230.171.124
- 4.144.132.114
- 85.210.193.152
- 20.42.179.192
- 74.178.76.128
- 13.89.179.15
- 135.233.95.135
- 52.123.128.14
- 20.112.250.133
- 4.150.223.113
- 203.26.79.13
- 135.232.92.34
- 52.110.12.51
- 52.110.12.40
- 172.178.240.161
- 52.148.114.188
- 72.154.7.98
- 92.223.78.30
- 4.150.223.104
- 172.175.111.170
- 4.207.44.74
- 52.110.12.45
- 52.110.12.25
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report