SUSPICIOUS — surijif.pdf
SUSPICIOUS — surijif.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (64/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
6feaf7896e283bf927f5c30320aaaa65d018eae4a604e150c0e965124b42d38c - SHA-1:
cd7c5fb88d2b32ed8e4a829c41ff1a3219b5a6ff - MD5:
2a8ba8726f2e6ecff8b881d0746dd221 - ssdeep:
768:1ogGzpDEpMoSAbgP+brPxaITtMDgOp+FOXMmt74hjbznzfniXvVDf3YB1H:HGF4pd0PYPB0Mmt74hvniXvVDfoB1H - TLSH:
T16D329DF321A7DD4CAA869B07ACBA15496446C78C7133DBB4548C7B2DC4BC6BCBE40960 - Submitted as: surijif.pdf
- File type: pdf · Size: 43361 bytes
- Verdict: suspicious (64/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 64/100 is the fusion of 5 weighted signals:
- Contacted 22 external host(s) at runtime (21 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=hd+wallpaper+for+android+mobile+god, https://site-1038796.mozfiles.com/files/1038796/41758982157.pdf, https://site-1036799.mozfiles.com/files/1036799/21416305983.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
8683 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\8f88d11932c8c0f94f2c323f8d7cd9f2.png -
bbe808833004e7db5922c3ee71a8976b70785988a59cdc4ca796ff575c5c05a2 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
a513e483798a312f9b37911e0a1d2120be9f03c7b9e9404bca30ba30599512f9
Embedded URLs
- https://gettraff.ru/strik?keyword=hd+wallpaper+for+android+mobile+god
- https://site-1038796.mozfiles.com/files/1038796/41758982157.pdf
- https://site-1036799.mozfiles.com/files/1036799/21416305983.pdf
- https://site-1036676.mozfiles.com/files/1036676/37765596171.pdf
- https://uploads.strikinglycdn.com/files/79b16719-2387-42a9-a5e6-505f51dc8a40/733843020.pdf
- https://uploads.strikinglycdn.com/files/2d5f1123-4eb6-4525-a1c4-b8f9df0a7e9a/99556909935.pdf
- https://uploads.strikinglycdn.com/files/e4c5f66f-88a1-4197-8751-5519a6112e41/98807490471.pdf
- https://uploads.strikinglycdn.com/files/25e3ae86-44cf-4a12-9bd6-823feb6ae8d3/11608789286.pdf
- https://uploads.strikinglycdn.com/files/ee977d0d-0048-4139-b8ed-347bb71d1d8b/36711975406.pdf
- https://uploads.strikinglycdn.com/files/0151da27-43e2-4a88-8377-f28428cfb601/48989508492.pdf
- https://uploads.strikinglycdn.com/files/31d016e6-3cf3-4e46-93b2-35feee92a0a5/97495865661.pdf
- https://uploads.strikinglycdn.com/files/d6213cdf-9db7-4ffe-80fa-07285a00d25a/fufusuwetamenuwijugebexu.pdf
- https://site-1041677.mozfiles.com/files/1041677/pefatati.pdf
- https://site-1039632.mozfiles.com/files/1039632/61903161963.pdf
- https://site-1048452.mozfiles.com/files/1048452/xiwujonuworoz.pdf
- https://site-1036946.mozfiles.com/files/1036946/xamonuvoroko.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- gettraff.ru
- site-1038796.mozfiles.com
- site-1036799.mozfiles.com
- site-1036676.mozfiles.com
- uploads.strikinglycdn.com
- site-1041677.mozfiles.com
- site-1039632.mozfiles.com
- site-1048452.mozfiles.com
- site-1036946.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.168.117.171
- 52.123.252.226
- 20.247.184.142
- 57.155.104.224
- 4.230.171.124
- 74.179.77.204
- 135.232.92.97
- 51.104.15.253
- 52.123.129.14
- 20.76.201.171
- 203.26.79.13
- 172.178.240.163
- 20.165.94.46
- 40.84.97.4
- 52.148.114.188
- 92.223.78.30
- 20.184.175.11
- 20.184.175.9
- 72.154.7.99
- 4.150.223.108
- 52.110.12.47
- 52.110.12.51
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report