MALICIOUS — normal_5f8a3017b2305.pdf
MALICIOUS — normal_5f8a3017b2305.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6cd72ad74ddf70161ec25baab7093cf16695efcee0a6c5609685176fad6fd423 - SHA-1:
df711a41da51edf5322a717372faa771e02fa20f - MD5:
9171e63d6802de294f1cc1a1a41b338a - ssdeep:
768:0xgGzpD5pA9ineyTGZXhwy3MFASW3arV/d5aEZfYf5ah5x52pgF59dfVci8k2Shs:XGF9pIpdhwy+d1rdD5nfVciayacG - TLSH:
T17C33BFF310A7ED8D7AC66B03ADE7155A0189C38C6126A7A105CCB73CE1BC5FDAE00951 - Submitted as: normal_5f8a3017b2305.pdf
- File type: pdf · Size: 48413 bytes
- Verdict: malicious (86/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 86/100 is the fusion of 7 weighted signals:
- Memory forensics: 3 finding(s), e.g. RWX/private injected region in SumatraPDF.exe (pid 9028) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Contacted 30 external host(s) at runtime (27 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/28c1be46-8e45-4643-9f8f-8223b4da0be3/fbla_entrepreneurship_study_guide.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.ru/123?keyword=best+paid+apps+android, https://uploads.strikinglycdn.com/files/28c1be46-8e45-4643-9f8f-8223b4da0be3/fbla_entrepreneurship_study_guide.pdf, https://uploads.strikinglycdn.com/files/a299535f-88ad-4083-a3a7-a61d603a71c8/kuxoziduliriwurawab.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (7 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
8729 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- settings-win.data.microsoft.com
- www.msn.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\d8069ebf18092525cd9ced0bc82fa4a9.png -
416fda8120667307dc2d83a9ff3ffbe86af95bd6d4e4bfcf6b999f8ecf579030 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
3aca846c612953dced208d7cb7e0c41c60cff47606f6187352f2b9c2b21ef3d7
Embedded URLs
- https://ttraff.ru/123?keyword=best+paid+apps+android
- https://uploads.strikinglycdn.com/files/28c1be46-8e45-4643-9f8f-8223b4da0be3/fbla_entrepreneurship_study_guide.pdf
- https://uploads.strikinglycdn.com/files/a299535f-88ad-4083-a3a7-a61d603a71c8/kuxoziduliriwurawab.pdf
- https://uploads.strikinglycdn.com/files/2202435b-3689-470b-9c60-75f9d01a6b1f/nowoxex.pdf
- https://cdn.shopify.com/s/files/1/0480/8245/2644/files/dungeon_quest_board_game_rules.pdf
- https://cdn.shopify.com/s/files/1/0429/5252/3929/files/sift_heads_0_download.pdf
- https://cdn.shopify.com/s/files/1/0496/2241/7561/files/30186863878.pdf
- https://cdn.shopify.com/s/files/1/0435/4224/9621/files/lalemabupepupowedaguzev.pdf
- https://cdn.shopify.com/s/files/1/0428/8321/9619/files/63111434766.pdf
- https://cdn.shopify.com/s/files/1/0436/3295/1446/files/conda_install_matplotlib_venn.pdf
- https://cdn.shopify.com/s/files/1/0428/1666/7814/files/78650561397.pdf
- https://cdn.shopify.com/s/files/1/0428/6890/0006/files/bibisuwixizopalozenu.pdf
- https://cdn.shopify.com/s/files/1/0497/4415/0689/files/33672431796.pdf
- https://cdn.shopify.com/s/files/1/0437/6992/1690/files/45182532714.pdf
- https://cdn.shopify.com/s/files/1/0488/3739/4597/files/kitejinaru.pdf
- https://cdn.shopify.com/s/files/1/0435/2684/8661/files/sum_latin_wiktionary.pdf
- https://cdn.shopify.com/s/files/1/0487/9296/1189/files/hubsan_x4_h107c_user_manual.pdf
- https://uploads.strikinglycdn.com/files/f2b76d75-2d4b-40e2-9e5f-472a3938b954/58253027774.pdf
- https://uploads.strikinglycdn.com/files/b4fd4b6a-7721-4421-8275-3ffb9620fe65/12913636883.pdf
- https://uploads.strikinglycdn.com/files/82977449-015e-4c0a-bda4-95a763f6f6c0/60642639184.pdf
- https://uploads.strikinglycdn.com/files/1e0b7fa0-ae81-4605-8532-14ef8a4ac124/92774624098.pdf
- https://uploads.strikinglycdn.com/files/41a8a42d-a04a-4e6e-9bc4-015a977f2341/xetanurinog.pdf
- https://uploads.strikinglycdn.com/files/04623c7f-03ca-4087-b8d2-50529022f217/68272405927.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ttraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.182.141.63
- 20.42.179.204
- 4.230.171.124
- 52.230.60.54
- 74.178.76.128
- 4.150.223.108
- 74.178.76.54
- 52.123.252.238
- 20.76.201.171
- 40.99.134.18
- 40.99.133.242
- 52.123.129.14
- 172.178.240.161
- 203.26.79.13
- 74.178.76.44
- 52.148.114.188
- 20.42.65.94
- 51.11.192.49
- 4.247.188.224
- 72.154.7.16
- 135.234.160.244
- 4.150.223.106
- 4.209.250.170
- 52.168.117.168
- 92.223.78.30
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report