SUSPICIOUS — 4463543.pdf
SUSPICIOUS — 4463543.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (68/100). 2 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
4fe7b8b70d46cc1f6db3c5235637a6ae1be600a3431519a50d3978366812e0e9 - SHA-1:
fdccc91390d93a12e39ddb7148eaf04cce620ee0 - MD5:
5162ab9b8ca73a377210300aa85ca1d4 - ssdeep:
768:AgGzpDspn2MjfrsqOJqAf8BinlmWLhzjIePley/ukFTAE/3XY48jS:NGF4p0mizUegkFTAeXY48jS - TLSH:
T1E1316CF34093EC8D3A8B5F036DEF115D944AD38CA137A6614498676CD5BCAFE2E10A20 - Submitted as: 4463543.pdf
- File type: pdf · Size: 41014 bytes
- Verdict: suspicious (68/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 68/100 is the fusion of 6 weighted signals:
- Contacted 21 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=creating%20line%20plot%20worksheets%205th%20grade, https://cdn.shopify.com/s/files/1/0434/4456/8220/files/lijefas.pdf, https://cdn.shopify.com/s/files/1/0437/1231/5545/files/bupebe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (13 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9686 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep(3)._dosvc._tcp.local
- desktop-hsgcbep(4)._dosvc._tcp.local
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
4b16e9309fc582fd97d12f32a548156bc3b82d5eacfa44cf02dbc14667f3f1c3 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\d63abaee20d1d8c9796673fd42a77910.png -
1a172083c56b2cbc3b513397bf7666ec4f635237ca87aa9356a7d2cf8d59700d - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ggtraff.ru/wb?keyword=creating%20line%20plot%20worksheets%205th%20grade
- https://cdn.shopify.com/s/files/1/0434/4456/8220/files/lijefas.pdf
- https://cdn.shopify.com/s/files/1/0437/1231/5545/files/bupebe.pdf
- https://cdn.shopify.com/s/files/1/0431/4683/8167/files/windows_8.1_pro_build_9600_activation.pdf
- https://s3.amazonaws.com/zarelusipofox/place_attachment_theory.pdf
- https://s3.amazonaws.com/felasorarabipis/adverbs_modifying_adjectives_worksheet.pdf
- https://s3.amazonaws.com/zirojopemup/castrol_magnatec_professional_5w40.pdf
- https://s3.amazonaws.com/xanebavifamopez/73340951774.pdf
- https://s3.amazonaws.com/mawesenasijoser/analise_combinatoria_exercicios_vestibular.pdf
- https://s3.amazonaws.com/susopuzupure/android_studio_tutorialspoint.pdf
- https://s3.amazonaws.com/subud/ayatoul_koursiyou.pdf
- https://cdn.shopify.com/s/files/1/0433/1415/1589/files/wps_wpa_old_version_download_apk.pdf
- https://cdn.shopify.com/s/files/1/0433/7808/1959/files/waves_tune_user_manual.pdf
- https://cdn.shopify.com/s/files/1/0500/5328/4008/files/farming_simulator_18_revdl_com_mod_apk.pdf
- https://cdn.shopify.com/s/files/1/0499/1683/8049/files/719061734.pdf
- https://cdn.shopify.com/s/files/1/0434/2536/6165/files/57894219320.pdf
- https://wedebiki.weebly.com/uploads/1/3/0/9/130969436/safoduxadotijisomi.pdf
- https://rimesozarabef.weebly.com/uploads/1/3/1/6/131607712/pimemelaju-galewiwimav-zefugififirod.pdf
- https://xavujome.weebly.com/uploads/1/3/0/7/130739328/kujupaxadomifuti.pdf
- https://bakuwosir.weebly.com/uploads/1/3/0/8/130874569/4546679.pdf
- https://vixijusodu.weebly.com/uploads/1/3/0/7/130776714/2393165.pdf
- https://cdn.shopify.com/s/files/1/0431/8868/2915/files/gerurifizazobomakebapevop.pdf
- https://cdn.shopify.com/s/files/1/0266/8353/9641/files/46558733981.pdf
- https://cdn.shopify.com/s/files/1/0496/1176/7961/files/nokia_3310_dual_sim_manual.pdf
- https://cdn.shopify.com/s/files/1/0462/3876/1109/files/kubetegasetexa.pdf
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- s3.amazonaws.com
- wedebiki.weebly.com
- rimesozarabef.weebly.com
- xavujome.weebly.com
- bakuwosir.weebly.com
- vixijusodu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.168.117.171
- 162.159.142.9
- 52.110.12.22
- 4.247.188.233
- 4.230.171.124
- 4.247.188.224
- 52.230.60.54
- 135.232.92.97
- 40.103.64.242
- 20.165.94.63
- 52.123.128.14
- 40.103.64.226
- 135.233.45.222
- 52.123.252.233
- 72.153.5.137
- 203.26.79.13
- 52.123.252.192
- 20.42.179.204
- 104.46.162.229
- 92.223.78.30
- 172.175.111.170
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report