SUSPICIOUS — normal_5f8753df8551b.pdf
SUSPICIOUS — normal_5f8753df8551b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (64/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
7d243af98cc1a7275ef11bb23f03f987a18ac625c575454c19a9fcea53406caf - SHA-1:
597bc08f27215cc3e6f21e214541397b445f3733 - MD5:
a76ef239ff88b9e37f5620f56e1b7257 - ssdeep:
1536:XGFup4zjlYiGI1Av3XWzIH+KNs7s81iZkFWPwrL:2FupYaiGI1AfXzHdCH0kcw - TLSH:
T1C4337DF310A7EC4CA9CF9B179DAA0159A18AD7892032D7A045CC776CD4BC6FE7E10921 - Submitted as: normal_5f8753df8551b.pdf
- File type: pdf · Size: 49347 bytes
- Verdict: suspicious (64/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 64/100 is the fusion of 5 weighted signals:
- Contacted 30 external host(s) at runtime (23 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=truck+driver+offroad+2+mod+apk, https://cdn-cms.f-static.net/uploads/4366362/normal_5f872b230cc99.pdf, https://cdn-cms.f-static.net/uploads/4366645/normal_5f873e679c4ff.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (15 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
8713 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\00b80853f5226a4b79d8995ff533d33c.png -
2b3a834180eb3be78cd4d1457fde1574c7e22c3e2b8b9e0827972cec2e70347f - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
3e320934c6648bfac8477febeab233e33927afa7e1ba75abb64b0e80fc0c452c
Embedded URLs
- https://ggtraff.ru/123?keyword=truck+driver+offroad+2+mod+apk
- https://cdn-cms.f-static.net/uploads/4366362/normal_5f872b230cc99.pdf
- https://cdn-cms.f-static.net/uploads/4366645/normal_5f873e679c4ff.pdf
- https://cdn-cms.f-static.net/uploads/4366402/normal_5f872f4b2ac50.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/010fdcdf.pdf
- https://site-1043091.mozfiles.com/files/1043091/90547337992.pdf
- https://site-1039907.mozfiles.com/files/1039907/36347896845.pdf
- https://site-1043352.mozfiles.com/files/1043352/psychology_of_learning_book.pdf
- https://site-1037886.mozfiles.com/files/1037886/76846707574.pdf
- https://site-1037120.mozfiles.com/files/1037120/64064677390.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/7971455.pdf
- https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/4230817.pdf
- https://gamupizesusaza.weebly.com/uploads/1/3/1/3/131398140/nabomet.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/8145298e.pdf
- https://site-1043324.mozfiles.com/files/1043324/54694308198.pdf
- https://site-1037149.mozfiles.com/files/1037149/4622036568.pdf
- https://site-1045390.mozfiles.com/files/1045390/todataporamodejegebuxu.pdf
- https://site-1043495.mozfiles.com/files/1043495/sawojevaxebuvig.pdf
- https://site-1042547.mozfiles.com/files/1042547/35693103932.pdf
- https://site-1037849.mozfiles.com/files/1037849/porajoxik.pdf
- https://site-1048292.mozfiles.com/files/1048292/95431352285.pdf
- https://site-1039711.mozfiles.com/files/1039711/nifazarak.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- dutitujazekap.weebly.com
- site-1043091.mozfiles.com
- site-1039907.mozfiles.com
- site-1043352.mozfiles.com
- site-1037886.mozfiles.com
- site-1037120.mozfiles.com
- rezizeme.weebly.com
- gamupizesusaza.weebly.com
- besiwalufeg.weebly.com
- site-1043324.mozfiles.com
- site-1037149.mozfiles.com
- site-1045390.mozfiles.com
- site-1043495.mozfiles.com
- site-1042547.mozfiles.com
- site-1037849.mozfiles.com
- site-1048292.mozfiles.com
- site-1039711.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 135.233.45.221
- 135.232.92.34
- 20.184.175.8
- 4.155.95.248
- 57.155.104.224
- 4.230.171.124
- 135.232.92.137
- 135.233.95.135
- 4.150.223.114
- 13.89.179.12
- 40.104.4.2
- 20.236.44.162
- 52.123.129.14
- 52.123.128.14
- 162.159.142.9
- 92.223.78.30
- 52.123.252.241
- 172.178.240.161
- 203.26.79.13
- 52.123.252.235
- 52.123.252.218
- 52.148.114.188
- 57.154.63.210
- 20.184.175.20
- 52.168.117.171
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report