MALICIOUS — normal_5f8ae68f47aa3.pdf
MALICIOUS — normal_5f8ae68f47aa3.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
4fbd20c01d2bf189a75227c25b6191cb981bcaf65172cf7b9b3c58af6a7b981e - SHA-1:
b7d09ea90b9884c06bd0937d218f2a1a2bcfda0b - MD5:
657b39ec3cf547003f03eb2b3561b57f - ssdeep:
768:pgGzpDep1/geGNt1qISGcYPnxGpmeCzfM1BnXi5Y26p72OSzxwXbhZp7dRfpkR7:KGFap12YDCwnRpaOSFgxfmR7 - TLSH:
T197328EF310A3ED4D778F9F07AEAB019A614AD78C612797600588672CD47CAFD7E00A61 - Submitted as: normal_5f8ae68f47aa3.pdf
- File type: pdf · Size: 44859 bytes
- Verdict: malicious (72/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 72/100 is the fusion of 6 weighted signals:
- Contacted 19 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/09d8542b-a76c-4903-b4ec-32eac8c6ec4c/75351541198.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.club/123?keyword=tubi+tv+apk+premium, https://cdn.shopify.com/s/files/1/0266/9363/2196/files/tyler_dewitt_chemistry_videos_list.pdf, https://cdn.shopify.com/s/files/1/0433/7231/4778/files/roland_barthes_mythologies_download.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (6 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9819 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- c.pki.goog
- desktop-hsgcbep._dosvc._tcp.local
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787773445&P2=404&P3=2&P4=YqelgvTpwh6Kz2wW6Jn2shvK2MNjhO7aPRpnE%2fX2RQV02EiQF1%2fNWsEA2oU8t35sXuHxr9%2fQIt0CzCRsT4jgzQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\c14d2eab9cc9b84f5d369e9bb1c25dec.png -
c31f5bcad3adabb50b6bcc9056ba995cfb4769f51d215f15e2779114f3bf7d20 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
be0709fb4705992ec56e66778699cce09804dd6cfb56a0f6989be7ace4566b68 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ttraff.club/123?keyword=tubi+tv+apk+premium
- https://cdn.shopify.com/s/files/1/0266/9363/2196/files/tyler_dewitt_chemistry_videos_list.pdf
- https://cdn.shopify.com/s/files/1/0433/7231/4778/files/roland_barthes_mythologies_download.pdf
- https://cdn.shopify.com/s/files/1/0488/4643/8565/files/backyard_travis_scott_lyrics.pdf
- https://cdn.shopify.com/s/files/1/0498/0064/2721/files/bagezevifaxenagim.pdf
- https://cdn.shopify.com/s/files/1/0484/9598/4795/files/chemical_engineering_thermodynamics.pdf
- https://cdn.shopify.com/s/files/1/0268/8175/3288/files/30kg_to_stone_and_lbs.pdf
- https://cdn.shopify.com/s/files/1/0497/4854/1594/files/fotifozuzaro.pdf
- https://cdn.shopify.com/s/files/1/0486/3161/1560/files/kogoz.pdf
- https://cdn.shopify.com/s/files/1/0434/7743/4525/files/21248608654.pdf
- https://uploads.strikinglycdn.com/files/09d8542b-a76c-4903-b4ec-32eac8c6ec4c/75351541198.pdf
- https://uploads.strikinglycdn.com/files/8e627c31-79fb-4d85-a30e-9dc9fa796114/gidejafofujatusugepakumu.pdf
- https://uploads.strikinglycdn.com/files/bc04da5e-5183-4730-af68-215380333c44/fikifizubowarojexuwegukiw.pdf
- https://uploads.strikinglycdn.com/files/ea1bb16c-ae25-44e8-bd5f-2e6b2c7e5047/54425481582.pdf
- https://uploads.strikinglycdn.com/files/cca2c5d0-5e63-486b-a8e9-429db2dff3f2/dulalipoziri.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/9051060.pdf
- https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/menojeluv_fitejezifug.pdf
- https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/4b201c87d.pdf
- https://cdn.shopify.com/s/files/1/0500/5069/5336/files/summertime_saga_apk_for_android_phone.pdf
- https://cdn.shopify.com/s/files/1/0481/6417/6021/files/13478203144.pdf
- https://cdn.shopify.com/s/files/1/0431/4837/8280/files/comment_faire_une_recherche_sur_internet.pdf
- https://uploads.strikinglycdn.com/files/eb1b5634-773d-4d29-9632-bdf477dde560/fagavitaterojirizatagoj.pdf
- https://uploads.strikinglycdn.com/files/7c5207d8-2e01-4309-9af8-4ed366718f6b/tademeto.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ttraff.club
- cdn.shopify.com
- uploads.strikinglycdn.com
- zoxuzuxebexot.weebly.com
- mupibidegupek.weebly.com
- povutepumik.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 72.154.7.100
- 162.159.142.9
- 172.66.2.5
- 52.110.12.55
- 57.154.63.210
- 74.178.232.29
- 4.230.171.124
- 203.26.79.13
- 135.233.95.135
- 20.76.201.171
- 52.123.129.14
- 40.99.134.18
- 74.178.76.128
- 135.234.160.247
- 20.52.64.200
- 142.250.195.163
- 135.234.160.245
- 172.170.180.133
- 20.50.73.5
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report