SUSPICIOUS — normal_5f8734c20ea1f.pdf
SUSPICIOUS — normal_5f8734c20ea1f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (64/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
aeec4f24371e9acc7a093e13c3221196f38a4aadf9438c59836104979a9a7aa6 - SHA-1:
6461b2e9adbed42b50ed6118ff1ada6f7bf9dd84 - MD5:
ad577fde9bcce71f3cb178b6126ed89c - ssdeep:
1536:sGFTprJbbjEzm7ClDkGBhJUJ6KFcMlCQiX:JFTprJ7YBDkIXUoKFEp - TLSH:
T14F33AFF304ABDD4C7A8E9B53ADAB115A948AC34861379760448CB63CD5BC2BE7F10970 - Submitted as: normal_5f8734c20ea1f.pdf
- File type: pdf · Size: 51565 bytes
- Verdict: suspicious (64/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 64/100 is the fusion of 5 weighted signals:
- Contacted 30 external host(s) at runtime (23 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=improve+your+vocabulary+book+pdf, https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/jibepare-vudaramuzi-refirezagulele.pdf, https://narogigadi.weebly.com/uploads/1/3/0/8/130874066/c2099e721b.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (10 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
8695 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- settings-win.data.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\e530d694b7b46f1ad5975705be0c5f48.png -
44b9f2d586ab8354a4d5a96b5c5038049224765eba3abc3cb8dbd4e91cd74007 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
00c687a2fa072f09af907b8d6ece8d343e9e02fb87a9c1ec66f499e94333c337
Embedded URLs
- https://ggtraff.ru/123?keyword=improve+your+vocabulary+book+pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/jibepare-vudaramuzi-refirezagulele.pdf
- https://narogigadi.weebly.com/uploads/1/3/0/8/130874066/c2099e721b.pdf
- https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/tajokakapuzavil_popolutev.pdf
- https://tudupumodowi.weebly.com/uploads/1/3/1/4/131406798/d2080fac38fbc08.pdf
- https://uploads.strikinglycdn.com/files/0de58f12-f535-4b47-9e12-4e67b467e1e2/fepibibivixazebijiku.pdf
- https://uploads.strikinglycdn.com/files/42f7f334-5986-4f02-bd84-0b2e47fa1074/gorebixerewamuxoguk.pdf
- https://uploads.strikinglycdn.com/files/4899b4d8-3b14-4357-9882-f9404e4d52b6/93515034308.pdf
- https://uploads.strikinglycdn.com/files/672f91eb-3653-4ee1-ae0b-07b2f4d002eb/titus.pdf
- https://site-1038992.mozfiles.com/files/1038992/9079007234.pdf
- https://site-1041404.mozfiles.com/files/1041404/sabasiv.pdf
- https://site-1039174.mozfiles.com/files/1039174/708879625.pdf
- https://site-1042556.mozfiles.com/files/1042556/97320140474.pdf
- https://site-1042011.mozfiles.com/files/1042011/36273401835.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/movew.pdf
- https://rewemekekebaz.weebly.com/uploads/1/3/1/4/131406535/2efecb114f5e5.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/fad7f7.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/mikukinib.pdf
- https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/145769.pdf
- https://cdn.shopify.com/s/files/1/0479/6979/6252/files/vurewebepogodojotuto.pdf
- https://cdn.shopify.com/s/files/1/0477/2226/6780/files/thermal_and_night_vision_goggles_combined.pdf
- https://cdn.shopify.com/s/files/1/0487/7261/2262/files/44319376012.pdf
- https://cdn.shopify.com/s/files/1/0483/1812/0100/files/gettube_apk_download.pdf
- https://cdn.shopify.com/s/files/1/0434/9899/5864/files/intex_challenger_k2.pdf
- https://cdn-cms.f-static.net/uploads/4366359/normal_5f8726e27d961.pdf
Embedded domains
- ggtraff.ru
- mogilifus.weebly.com
- narogigadi.weebly.com
- povutepumik.weebly.com
- tudupumodowi.weebly.com
- uploads.strikinglycdn.com
- site-1038992.mozfiles.com
- site-1041404.mozfiles.com
- site-1039174.mozfiles.com
- site-1042556.mozfiles.com
- site-1042011.mozfiles.com
- jatorogerujew.weebly.com
- rewemekekebaz.weebly.com
- besiwalufeg.weebly.com
- keniwuki.weebly.com
- walijogopabo.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 203.26.79.13
- 13.89.179.15
- 104.208.16.94
- 40.84.85.40
- 4.230.171.124
- 20.247.184.142
- 85.210.196.11
- 52.253.84.76
- 74.179.77.204
- 20.165.94.54
- 52.168.112.66
- 20.236.44.162
- 40.103.64.226
- 52.123.129.14
- 52.123.128.14
- 135.233.95.144
- 52.123.252.239
- 135.234.160.245
- 162.159.142.9
- 135.232.92.34
- 52.123.252.215
- 52.148.114.188
- 92.223.78.30
- 172.215.188.225
- 72.154.7.106
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report