SUSPICIOUS — normal_5f8cafbb76f06.pdf
SUSPICIOUS — normal_5f8cafbb76f06.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
81db9313e42dfd8afcc9908f8f19ec801cdd32c13647a9b3b7370d12da2f1141 - SHA-1:
053da972ba6d1a1edc599d1d3a6882eef010ecd4 - MD5:
87dd3670b786ff35f03099e4f9016678 - ssdeep:
1536:IGFqpQo8DAyCHwIZwRdg8E18PGq8S2uVKZW/YCWFIc2lV:lFqp1iwHwK0dg8E18z8GKSKIco - TLSH:
T1F1339DF35097EC8D3E869B13ADEB105A64CAD788213797A044C8776C94BC5FCBE50960 - Submitted as: normal_5f8cafbb76f06.pdf
- File type: pdf · Size: 50945 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.ru/123?keyword=easyjet+expenses+claim+form+pdf, https://uploads.strikinglycdn.com/files/95aa7d94-61fd-4298-8dfa-e0c1b43dd2c2/fiwarolukepagapewof.pdf, https://uploads.strikinglycdn.com/files/ad35870a-4548-43d5-9d1e-d1f1803ce346/leregeko.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
1071 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- 224.0.0.251
- ff02::fb
- ff02::2
- ff02::1
- 10.240.0.1
- ff02::16
- 185.125.190.56
- 224.0.0.22
- 255.255.255.255
- ff02::1:2
- 91.189.91.157
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ttraff.ru/123?keyword=easyjet+expenses+claim+form+pdf
- https://uploads.strikinglycdn.com/files/95aa7d94-61fd-4298-8dfa-e0c1b43dd2c2/fiwarolukepagapewof.pdf
- https://uploads.strikinglycdn.com/files/ad35870a-4548-43d5-9d1e-d1f1803ce346/leregeko.pdf
- https://uploads.strikinglycdn.com/files/c8c0a9ec-bcdd-4cdb-b3b3-ce65aaeca7a8/22002041699.pdf
- https://uploads.strikinglycdn.com/files/b1398ab7-725d-4236-868d-52eb8d54a02f/8887252639.pdf
- https://cdn-cms.f-static.net/uploads/4376600/normal_5f8b3438a1894.pdf
- https://cdn-cms.f-static.net/uploads/4368782/normal_5f8cad5d1bcb7.pdf
- https://cdn-cms.f-static.net/uploads/4371020/normal_5f8b669c6c44b.pdf
- https://femevidawivuk.weebly.com/uploads/1/3/1/0/131071063/c195920f92d616.pdf
- https://tarirubawapub.weebly.com/uploads/1/3/1/6/131606173/a5e1ec36.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/dolopitubolagu.pdf
- https://wegupufula.weebly.com/uploads/1/3/0/8/130813429/530b9cf.pdf
- https://tarirubawapub.weebly.com/uploads/1/3/1/6/131606173/8474629.pdf
- https://kuvofexe.weebly.com/uploads/1/3/1/1/131163751/7837367.pdf
- https://cdn.shopify.com/s/files/1/0501/5289/8739/files/dovanigiluluzixekemeju.pdf
- https://cdn.shopify.com/s/files/1/0479/0114/7302/files/x_bar_in_microsoft_word.pdf
- https://cdn.shopify.com/s/files/1/0495/9155/0104/files/2414358337.pdf
- https://cdn.shopify.com/s/files/1/0429/9092/8026/files/dabona.pdf
- https://cdn.shopify.com/s/files/1/0493/6073/2319/files/medabuxutojelurava.pdf
- https://cdn.shopify.com/s/files/1/0499/8837/0582/files/doterra_essential_oils_guide_a-z.pdf
- https://cdn.shopify.com/s/files/1/0435/5833/8715/files/track_walmart_order_with_confirmation_number.pdf
- https://cdn.shopify.com/s/files/1/0480/9742/7619/files/toca_life_vacation_apk_aptoide.pdf
- https://cdn.shopify.com/s/files/1/0493/0699/2799/files/game_of_thrones_season_8_free_online_australia.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ttraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- femevidawivuk.weebly.com
- tarirubawapub.weebly.com
- dutitujazekap.weebly.com
- wegupufula.weebly.com
- kuvofexe.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report