SUSPICIOUS — 56515088270.pdf
SUSPICIOUS — 56515088270.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (64/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
39961079821ae8582274fc33cb8cb968839170bb1e66a6fa4dc5b3a591a95806 - SHA-1:
40e8d599d7afc3fb40a376002c376da6459735c2 - MD5:
571765ca3117905463c8792d87e3a7ac - ssdeep:
768:dgGzpDtkJxYJ7rAa6ba2kXr1EkFuLf1DMMTCulYVL:eGFhqMEa2ir1BqM7ulYVL - TLSH:
T15E328DF3509BEC8C7AD69B0399BB106A6589D74C7233AB64459C7B2C84BC2FD6F01850 - Submitted as: 56515088270.pdf
- File type: pdf · Size: 43480 bytes
- Verdict: suspicious (64/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 64/100 is the fusion of 5 weighted signals:
- Contacted 27 external host(s) at runtime (27 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=how+to+uninstall+oiv+mods, http://files.northtexasdoodles.com/uploads/1/3/1/4/131408100/gitijupas-weriwopo-veniziw.pdf, http://nefiti.goministries.us/uploads/1/3/1/4/131406665/jupoda-pikexepawufefo-gugedoxijov.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
8702 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
23b107dd79e868d3c791755faabf857757d9e1afcd51214590629780f09cc3fe - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\f10df20e3e2c7299ef1edeab9d6bc151.png -
485f700749a947c37e451c953ef23358aef5c531536f349c9b0424fbc49df132
Embedded URLs
- https://cctraff.ru/strik?keyword=how+to+uninstall+oiv+mods
- http://files.northtexasdoodles.com/uploads/1/3/1/4/131408100/gitijupas-weriwopo-veniziw.pdf
- http://nefiti.goministries.us/uploads/1/3/1/4/131406665/jupoda-pikexepawufefo-gugedoxijov.pdf
- http://files.loftmedspa.com/uploads/1/3/2/6/132695248/gativanugiw-ronuk.pdf
- http://tapovig.christinacarnesphotography.com/uploads/1/3/1/4/131438873/2113551.pdf
- http://nedep.compliancemastersllc.com/uploads/1/3/2/6/132683008/xajiterikorabof-sodupekosusax-gofagozoxuba.pdf
- http://zafoxo.omundoeolimite.com/uploads/1/3/1/8/131855997/fuwurowunewil.pdf
- http://files.shishisalon.net/uploads/1/3/2/7/132712050/5c7883b6c9586.pdf
- http://files.narokgames.com/uploads/1/3/2/7/132712154/18ce25.pdf
- http://files.eggharboryachtclub.org/uploads/1/3/2/8/132814518/fobewo-niwimavosed.pdf
- http://dowar.shoppingforagift.com/uploads/1/3/0/7/130739173/7847082.pdf
- http://tovamisa.iloveyogamaya.com/uploads/1/3/1/3/131380183/subolalezuzugemo.pdf
- http://files.midtownrealtycompany.com/uploads/1/3/1/0/131070289/1832704.pdf
- http://vewuva.serenefoxgames.com/uploads/1/3/1/4/131406861/xuwikojilubi.pdf
- http://files.stkate-las.com/uploads/1/3/0/9/130969059/5a63656549f.pdf
- http://files.roofglo.com/uploads/1/3/2/6/132683252/7995463.pdf
- https://uploads.strikinglycdn.com/files/3d08d21a-2114-4a5e-8da5-feab0054d2b3/55088567836.pdf
- https://uploads.strikinglycdn.com/files/22dbe1b5-a547-432b-a7aa-1b05ff819645/wilagalelofelasuguna.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- cctraff.ru
- files.northtexasdoodles.com
- nefiti.goministries.us
- files.loftmedspa.com
- tapovig.christinacarnesphotography.com
- nedep.compliancemastersllc.com
- zafoxo.omundoeolimite.com
- files.shishisalon.net
- files.narokgames.com
- files.eggharboryachtclub.org
- dowar.shoppingforagift.com
- tovamisa.iloveyogamaya.com
- files.midtownrealtycompany.com
- vewuva.serenefoxgames.com
- files.stkate-las.com
- files.roofglo.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 4.150.223.107
- 52.230.59.222
- 4.247.188.224
- 4.230.171.124
- 172.215.188.225
- 74.178.76.44
- 135.233.95.144
- 74.178.240.51
- 4.150.223.98
- 203.26.79.13
- 20.184.175.12
- 20.236.44.162
- 52.123.128.14
- 135.233.45.222
- 172.217.25.195
- 52.148.114.188
- 92.223.78.30
- 72.154.7.106
- 52.110.12.24
- 52.110.12.40
- 172.178.240.163
- 48.192.143.121
- 20.184.175.6
- 20.184.175.22
- 52.168.117.170
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report