SUSPICIOUS — 7613128.pdf
SUSPICIOUS — 7613128.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (56/100). 3 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
8abe6a923a8be623b1b1384b66c0fc2eeddd10db9b92654866feab9a6f4020da - SHA-1:
78057db94375f26c38bce6d9349e25e35a6d95d8 - MD5:
b5589a4ef5b8dfa416b60344751a646a - ssdeep:
1536:RGFrpRUC5HV7J+Ncftq2NzXLgSm7FOQA:0FrpP51Vz/NVGg - TLSH:
T1FD34BFF30093EC4DBB4BAB479CE7109A5586D288A032E79108A8776CD5BC7BD6F40D60 - Submitted as: 7613128.pdf
- File type: pdf · Size: 52683 bytes
- Verdict: suspicious (56/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 56/100 is the fusion of 6 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=sony%20ilce%20qx1, https://site-1038558.mozfiles.com/files/1038558/41934509751.pdf, https://site-1036885.mozfiles.com/files/1036885/gidexivuvuk.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 16 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9623 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- searchapp.bundleassets.example
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
Dropped files
- /opt/CAPEv2/storage/analyses/36958/files/e1f4e8ab8becd20f82e92aea9684cecba2dfeb18d3f3a078388ae60d9fbf8ca6 -
e1f4e8ab8becd20f82e92aea9684cecba2dfeb18d3f3a078388ae60d9fbf8ca6 - /opt/CAPEv2/storage/analyses/36958/files/09d0bf281e50cd32045b36a8e0f3add8cf9da4ee0f8a20341f8c4c28dc7e0bec -
09d0bf281e50cd32045b36a8e0f3add8cf9da4ee0f8a20341f8c4c28dc7e0bec - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://cctraff.ru/wb?keyword=sony%20ilce%20qx1
- https://site-1038558.mozfiles.com/files/1038558/41934509751.pdf
- https://site-1036885.mozfiles.com/files/1036885/gidexivuvuk.pdf
- https://site-1043917.mozfiles.com/files/1043917/zafafenuv.pdf
- https://site-1040528.mozfiles.com/files/1040528/gitesunufasole.pdf
- https://cdn.shopify.com/s/files/1/0498/8665/8718/files/loctite_epoxy_plastic_bonder_amazon.pdf
- https://cdn.shopify.com/s/files/1/0437/7057/7045/files/typing_learning_books.pdf
- https://cdn.shopify.com/s/files/1/0435/4077/5071/files/bells_test_time.pdf
- https://cdn.shopify.com/s/files/1/0433/8666/7158/files/va_handbook_private_road_maintenance_agreement.pdf
- https://cdn.shopify.com/s/files/1/0431/4726/4166/files/blues_clues_what_does_blue_want_to_make.pdf
- https://cdn.shopify.com/s/files/1/0435/1721/4874/files/77808542385.pdf
- https://cdn.shopify.com/s/files/1/0486/3728/0414/files/lord_of_the_flies_discussion_questions_by_chapter.pdf
- https://cdn.shopify.com/s/files/1/0266/8124/5870/files/sifetorijasa.pdf
- https://site-1039998.mozfiles.com/files/1039998/52831652946.pdf
- https://site-1040438.mozfiles.com/files/1040438/62013278619.pdf
- https://site-1038488.mozfiles.com/files/1038488/26078887314.pdf
- https://site-1042346.mozfiles.com/files/1042346/medirarupaganaraburudad.pdf
- https://site-1042890.mozfiles.com/files/1042890/pilakinox.pdf
- https://uploads.strikinglycdn.com/files/490af568-3719-4b48-a0f1-d68be22e2bdc/kafupuvikimukoletok.pdf
- https://uploads.strikinglycdn.com/files/09057c39-b64b-4a22-96de-e5ee0038da9c/sukefosedoz.pdf
- https://uploads.strikinglycdn.com/files/711bf60b-85d3-4516-b2e7-19f516147ab0/vorojuvunipavogamaluwekox.pdf
- https://uploads.strikinglycdn.com/files/c4797b4d-c1bf-493b-9388-9ac155440fc4/12180913396.pdf
- https://cdn.shopify.com/s/files/1/0266/9055/1981/files/scale_drawings_worksheet_7th_grade.pdf
- https://cdn.shopify.com/s/files/1/0472/2914/1157/files/second_act_rating_parents_guide.pdf
- https://cdn.shopify.com/s/files/1/0483/0688/0667/files/40646921199.pdf
Embedded domains
- cctraff.ru
- site-1038558.mozfiles.com
- site-1036885.mozfiles.com
- site-1043917.mozfiles.com
- site-1040528.mozfiles.com
- cdn.shopify.com
- site-1039998.mozfiles.com
- site-1040438.mozfiles.com
- site-1038488.mozfiles.com
- site-1042346.mozfiles.com
- site-1042890.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 72.145.35.97
- 52.123.129.14
- 52.110.12.14
- 57.155.104.224
- 74.178.240.51
- 135.233.45.223
- 4.230.171.124
- 20.247.184.197
- 135.233.95.80
- 72.154.7.114
- 52.123.128.14
- 85.210.196.11
- 52.123.252.226
- 52.168.117.168
- 20.42.73.26
- 203.26.79.13
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report