MALICIOUS — normal_5f877abd19b18.pdf
MALICIOUS — normal_5f877abd19b18.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (82/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7729a619a4c3b6dd8100b2b5a416e0d04f24b162d309ceef20c1c4050a759ebc - SHA-1:
51b012e4e4d2b6f21fe003b1f42ce4ff44543c93 - MD5:
44642d9ea4768445e2ae77c4e0621edc - ssdeep:
768:igGzpDNeCsgMFt9o+YxWeUIzhh5D3E0DbH3Z0NOG3joGDF4UdQNXqvO3i1lG:/GFReC3Q0Dl0NOG3jowFFdQNE71lG - TLSH:
T157338DF350D7DD4C7A8B9B43BDBB1055248ACB893226EBA045887B2CC4BC6BD7E50950 - Submitted as: normal_5f877abd19b18.pdf
- File type: pdf · Size: 50177 bytes
- Verdict: malicious (82/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 82/100 is the fusion of 6 weighted signals:
- Memory forensics: 3 finding(s), e.g. RWX/private injected region in SumatraPDF.exe (pid 4372) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Contacted 28 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=herman+miller+aeron+office+chair+instructions, https://cdn-cms.f-static.net/uploads/4366008/normal_5f877805a2bb9.pdf, https://cdn-cms.f-static.net/uploads/4366964/normal_5f874d919322c.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (15 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9627 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- c.pki.goog
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\9fb2ee1f1e29d4256e7abb77f0718539.png -
d7b426cfadadb3428d901969faccb07ff0c9fd1384bbf92e691f2c0ba605cdd1 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
132f8feb2f31c352f59bcde3cae5ddd9bf0ad4f7af15d72d5e7fed7f61907510 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ggtraff.ru/123?keyword=herman+miller+aeron+office+chair+instructions
- https://cdn-cms.f-static.net/uploads/4366008/normal_5f877805a2bb9.pdf
- https://cdn-cms.f-static.net/uploads/4366964/normal_5f874d919322c.pdf
- https://cdn-cms.f-static.net/uploads/4366005/normal_5f86f8dbaa4a2.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f86f516230e2.pdf
- https://cdn-cms.f-static.net/uploads/4365627/normal_5f875818324c4.pdf
- https://cdn-cms.f-static.net/uploads/4366364/normal_5f87702c8123b.pdf
- https://cdn-cms.f-static.net/uploads/4365659/normal_5f86fa9d9c768.pdf
- https://cdn-cms.f-static.net/uploads/4366369/normal_5f876a115642f.pdf
- https://cdn-cms.f-static.net/uploads/4367310/normal_5f876eb124dae.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/1441493.pdf
- https://xebikazogede.weebly.com/uploads/1/3/2/7/132740990/29a74792af419.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/ff06dfdf.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/gajiwegevogepe.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/4102594.pdf
- https://uploads.strikinglycdn.com/files/c6c6c6d2-719f-4d84-9f39-a390809af0e1/64132291997.pdf
- https://uploads.strikinglycdn.com/files/f348ef1e-dc6d-4da8-9b51-30f71aabb323/95221159664.pdf
- https://uploads.strikinglycdn.com/files/2478ad82-56c0-4ff4-a70b-e7bb628ce14a/rukezovitixakijetok.pdf
- https://site-1041210.mozfiles.com/files/1041210/gujabunubabagawefexova.pdf
- https://site-1042584.mozfiles.com/files/1042584/82427358112.pdf
- https://site-1040179.mozfiles.com/files/1040179/37975947098.pdf
- https://site-1037846.mozfiles.com/files/1037846/28655038814.pdf
- https://cdn-cms.f-static.net/uploads/4366382/normal_5f874106a1d6c.pdf
- https://cdn-cms.f-static.net/uploads/4368265/normal_5f876bb886c49.pdf
- https://cdn-cms.f-static.net/uploads/4366313/normal_5f873947b6e52.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- xojerajap.weebly.com
- xebikazogede.weebly.com
- genigudepa.weebly.com
- mogilifus.weebly.com
- uploads.strikinglycdn.com
- site-1041210.mozfiles.com
- site-1042584.mozfiles.com
- site-1040179.mozfiles.com
- site-1037846.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.182.143.212
- 52.148.114.188
- 52.168.117.168
- 40.84.85.40
- 74.178.232.29
- 52.168.117.170
- 92.223.78.30
- 20.42.73.27
- 52.123.252.233
- 52.110.12.38
- 52.123.252.203
- 4.230.171.124
- 20.42.179.192
- 72.153.5.131
- 203.26.79.13
- 52.123.252.231
- 52.168.117.174
- 135.232.92.137
- 20.236.44.162
- 20.42.65.84
- 52.123.252.216
- 52.123.129.14
- 172.178.240.162
- 52.123.252.244
- 142.250.195.227
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report