MALICIOUS — normal_5f8731746e949.pdf
MALICIOUS — normal_5f8731746e949.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
b0d629c4b0bf0b5209d8611952764135b1963263a409b1bfc86bedfc93c081b9 - SHA-1:
4cb74c9cff6ece72d1f29f00e800b6f5853b9f94 - MD5:
a1123d199aede52ef3ab03cc3683d4e2 - ssdeep:
768:9gGzpDdppInEvZjgMTqF15N+qIwHzj9q7FNcrH2RIFRS8njO4:+GFZp+RNfIwT4NcrWRITznjO4 - TLSH:
T1C2318DF310ABDE4CBACBAB076EEA21695489D64C91329764449D772CC47C7BD3E01A20 - Submitted as: normal_5f8731746e949.pdf
- File type: pdf · Size: 42235 bytes
- Verdict: malicious (92/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 7 weighted signals:
- Embedded link rated malicious by URL analysis: https://cdn-cms.f-static.net/uploads/4366388/normal_5f8717ccdb323.pdf - network signal, weight 0.70, confidence 0.80
- Memory forensics: 4 finding(s), e.g. RWX/private injected region in SumatraPDF.exe (pid 3512) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Contacted 19 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=heroes+evolved+apk+download+latest+version, https://cdn-cms.f-static.net/uploads/4366351/normal_5f870ee92667d.pdf, https://cdn-cms.f-static.net/uploads/4366388/normal_5f8717ccdb323.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (17 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9806 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 255.255.254.169.in-addr.arpa
- 251.0.0.224.in-addr.arpa
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
ac9a92c68973b5e91050f7c11e74d99d99c4c18c660d08b2471d246d859e0411 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\9ada71bb46b98da37060dd79d86b1be8.png -
cf20c66658a087f1d05bb7739d8a0558907516061adc6a95c98f3d6763e9bbb9 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ggtraff.ru/123?keyword=heroes+evolved+apk+download+latest+version
- https://cdn-cms.f-static.net/uploads/4366351/normal_5f870ee92667d.pdf
- https://cdn-cms.f-static.net/uploads/4366388/normal_5f8717ccdb323.pdf
- https://cdn-cms.f-static.net/uploads/4365653/normal_5f872344c6eeb.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f87064893f9a.pdf
- https://cdn-cms.f-static.net/uploads/4365657/normal_5f86ffea8c8e6.pdf
- https://site-1043649.mozfiles.com/files/1043649/vuboruratezuwemizifur.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/eaff109ab94007.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/1930383.pdf
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/4107459.pdf
- https://site-1038890.mozfiles.com/files/1038890/56740770869.pdf
- https://site-1040777.mozfiles.com/files/1040777/39353959776.pdf
- https://site-1038789.mozfiles.com/files/1038789/55232587288.pdf
- https://cdn-cms.f-static.net/uploads/4365660/normal_5f8714e0046d4.pdf
- https://cdn-cms.f-static.net/uploads/4366302/normal_5f870d8dc5306.pdf
- https://cdn-cms.f-static.net/uploads/4365549/normal_5f870983d360d.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f870db5908d1.pdf
- https://site-1048176.mozfiles.com/files/1048176/84016338457.pdf
- https://site-1042348.mozfiles.com/files/1042348/49715277494.pdf
- https://site-1039179.mozfiles.com/files/1039179/josaxenugigibuxega.pdf
- https://site-1037088.mozfiles.com/files/1037088/79424310439.pdf
- https://site-1039931.mozfiles.com/files/1039931/93487850919.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- site-1043649.mozfiles.com
- nudojafobedem.weebly.com
- jaserasozupog.weebly.com
- viweposedijul.weebly.com
- site-1038890.mozfiles.com
- site-1040777.mozfiles.com
- site-1038789.mozfiles.com
- site-1048176.mozfiles.com
- site-1042348.mozfiles.com
- site-1039179.mozfiles.com
- site-1037088.mozfiles.com
- site-1039931.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 2.0.7.0
- 135.233.95.144
- 162.159.142.9
- 4.150.223.97
- 52.110.12.22
- 57.154.63.210
- 4.230.171.124
- 4.247.188.233
- 4.150.223.100
- 20.76.201.171
- 40.99.133.210
- 20.184.175.19
- 52.123.129.14
- 135.233.95.80
- 203.26.79.13
- 74.179.77.204
- 135.234.160.245
- 4.150.223.101
- 48.199.12.1
- 4.150.223.105
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report