SUSPICIOUS — normal_5f8e4930ed058.pdf
SUSPICIOUS — normal_5f8e4930ed058.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (64/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4610e6650815123129aa918392a714fdcf437e74303ec9b420aa6d917ad2d326 - SHA-1:
689c6819d3eb0e80d02c3037451ebd5587f5c61b - MD5:
e585e202f521f0cfff551418a28f54fe - ssdeep:
768:hgGzpDZpiYaZR+WBoqu0D1A24sQRP0+khmOs7C3PxMle4IuWF0vaffx:SGFVpXatBsahm57C3JceF0vaf5 - TLSH:
T1DB319EF350A7EC9D3A86AB03ADA615596049DB8DA132E76044DC763CC4BC2BD7F009A1 - Submitted as: normal_5f8e4930ed058.pdf
- File type: pdf · Size: 41120 bytes
- Verdict: suspicious (64/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 64/100 is the fusion of 5 weighted signals:
- Contacted 17 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://ttraff.club/123?keyword=slither+io+mod+apk+god+mode, https://fakimodixoto.weebly.com/uploads/1/3/0/7/130739088/ruwajosul.pdf, https://kupugaxome.weebly.com/uploads/1/3/0/9/130969415/09809c.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (3 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9702 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- _dosvc._tcp.local
- desktop-hsgcbep
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787763873&P2=404&P3=2&P4=nuDoXqW405NT1pSKjYj5IvStSjtEfprvT90EXmEVV6iA2NZqvj2d%2fiGpo0FUIUBfA7ZF5oxB%2b8fMm%2feoy08C4Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787763945&P2=404&P3=2&P4=XS4sILj3t8sMa5cRzUQL1cx76Eh0QxT85vhwp1M%2b3sY2qrPxZV51wHye3W9KeeXJzPRBKJkOBEZ8qOYWlL%2b6Ww%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
5169ef032581d42d2fef0e774fa7cd34b660c2ba553c138c248b0a5ae5305d7f - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\31b27f2107ce47bc296d0e7cbd9df932.png -
3bd672fa7bf83b5cd366b3d8338bf08ff5a82e5c7ff6c6de4ffb1d3c421f572e - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ttraff.club/123?keyword=slither+io+mod+apk+god+mode
- https://fakimodixoto.weebly.com/uploads/1/3/0/7/130739088/ruwajosul.pdf
- https://kupugaxome.weebly.com/uploads/1/3/0/9/130969415/09809c.pdf
- https://wuvirinofibugiz.weebly.com/uploads/1/3/1/0/131070402/ruluvojasexanudup.pdf
- https://pisanofinupu.weebly.com/uploads/1/3/1/4/131437881/tarilidarila-kevamuvowezad-dugizamalenutaz-zujunoxuze.pdf
- https://cdn.shopify.com/s/files/1/0500/0190/3766/files/wiwogugome.pdf
- https://cdn.shopify.com/s/files/1/0499/8463/5040/files/88154533683.pdf
- https://cdn.shopify.com/s/files/1/0502/1155/3473/files/bezudokise.pdf
- https://cdn-cms.f-static.net/uploads/4366980/normal_5f8829e2b1b60.pdf
- https://cdn-cms.f-static.net/uploads/4389080/normal_5f8e3df0b6478.pdf
- https://cdn.shopify.com/s/files/1/0434/4872/9767/files/formato_cartas_descriptivas_ejemplos.pdf
- https://cdn.shopify.com/s/files/1/0435/5260/4328/files/fomigesemoref.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/lomuwanokik.pdf
- https://vaxajiwozoli.weebly.com/uploads/1/3/1/6/131637631/xexewen.pdf
- https://vogizezadu.weebly.com/uploads/1/3/0/8/130814341/cab01ed608.pdf
- https://buveziketi.weebly.com/uploads/1/3/1/3/131398526/dibixofodaw_gizavoteg.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/8767144.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Embedded domains
- ttraff.club
- fakimodixoto.weebly.com
- kupugaxome.weebly.com
- wuvirinofibugiz.weebly.com
- pisanofinupu.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- xojerajap.weebly.com
- vaxajiwozoli.weebly.com
- vogizezadu.weebly.com
- buveziketi.weebly.com
- dimaxafazeza.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 203.26.79.13
- 4.150.223.97
- 172.172.255.217
- 57.155.101.212
- 52.182.143.212
- 20.50.201.195
- 48.211.4.16
- 162.159.142.9
- 52.110.12.54
- 4.230.171.124
- 51.104.15.253
- 135.233.95.144
- 52.123.128.14
- 52.182.141.63
- 72.145.35.109
- 135.234.160.244
- 104.46.162.229
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report