SUSPICIOUS — normal_5f86f6036addc.pdf
SUSPICIOUS — normal_5f86f6036addc.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (64/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
95750f8cdd24fb3968ef03757ff7e780ae179e018d4da77a2be7309ddddc1d75 - SHA-1:
b65f98e1e9ac1022b984a66d4c925b0608ae362d - MD5:
6d04a563d254e20bed58a598d90e5c1e - ssdeep:
768:igGzpDHpHzX6F6Gg25+6w0PQpaf1g7saAGqXo0KNumA3Pc6:/GFTpW06RQpCva5qXJ+umA3Pc6 - TLSH:
T16E307DF35067EC8C7A8B9F039EA71158614AD78D6033866058DC376CE5BC2ED3E04A62 - Submitted as: normal_5f86f6036addc.pdf
- File type: pdf · Size: 37343 bytes
- Verdict: suspicious (64/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 64/100 is the fusion of 5 weighted signals:
- Contacted 12 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/123?keyword=microsoft+office+2020+step+by+step+pdf, https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/3532345.pdf, https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/1109957.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (3 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9688 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\06e59cc5b8a4426feb72bf3d15d1dadf.png -
7c05175f44c983007c9a72be5cdaf833ebad52d0a3e43b000d0031bca2e47406 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
167ae2b606e8ba2a463d026d24d5b6f245419c1fd1b3047ca27e96fa049637ce - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://gettraff.ru/123?keyword=microsoft+office+2020+step+by+step+pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/3532345.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/1109957.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/divili_dapixi.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/jasamejug-jenutuzudemeluf.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/d1ee3c84.pdf
- https://cdn.shopify.com/s/files/1/0432/5795/4464/files/data_analyst_cover_letter_reddit.pdf
- https://cdn.shopify.com/s/files/1/0486/2463/1976/files/led_light_globes_replacement.pdf
- https://cdn.shopify.com/s/files/1/0504/8238/0965/files/62020414419.pdf
- https://cdn.shopify.com/s/files/1/0484/3428/2654/files/ojo_de_pescado_on_foot.pdf
- https://cdn.shopify.com/s/files/1/0496/5633/2437/files/wobirif.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/vanojiraxajerubefiza.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/gosibokuvefuj.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/fibawubaxavuvabu.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/filosom-lusiwikafese-jerupuxorukoti-novubolifunuw.pdf
- https://site-1043246.mozfiles.com/files/1043246/wavukezanunonimejuxatexid.pdf
- https://site-1040313.mozfiles.com/files/1040313/sebelodipuburukekoker.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Embedded domains
- gettraff.ru
- zoxuzuxebexot.weebly.com
- bedizegoresupa.weebly.com
- jakedekokobara.weebly.com
- jawasolasazilem.weebly.com
- cdn.shopify.com
- keniwuki.weebly.com
- guwomenod.weebly.com
- site-1043246.mozfiles.com
- site-1040313.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 51.105.71.137
- 4.230.171.124
- 4.144.132.114
- 74.178.240.61
- 20.76.201.171
- 52.123.129.14
- 72.145.35.104
- 203.26.79.13
- 52.123.252.226
- 172.178.240.162
- 4.209.250.170
- 4.150.223.102
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report