SUSPICIOUS — 67402198876.pdf
SUSPICIOUS — 67402198876.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (68/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
b644d9b2b111d932965aa3ed888cb924dc5ee4787f72830e89e877b79f67a6ea - SHA-1:
cbc61a10f4390a80d6530b0ecf59780085a97cce - MD5:
8611f74d2060d7163b808d91f4bad38c - ssdeep:
768:/gGzpDUIhx9PcMA6u0LEV+wC2y6qLZotyW0FC3zoPX:IGF42u0gYwvy6qd6y03zoPX - TLSH:
T1452F7CF320ABEE4D6A86DB039DEA10686185C74C6236A76458CC3B6DD4FC2FD6F40851 - Submitted as: 67402198876.pdf
- File type: pdf · Size: 35549 bytes
- Verdict: suspicious (68/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 68/100 is the fusion of 6 weighted signals:
- Contacted 10 external host(s) at runtime (1 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=vcf+file+to+pdf+online, https://cdn.shopify.com/s/files/1/0483/3751/8752/files/57522001202.pdf, https://cdn.shopify.com/s/files/1/0481/7718/4925/files/is_a_central_city_a_cbd_oil.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (11 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9867 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- searchapp.bundleassets.example
- inference.location.live.net
- 250.255.255.239.in-addr.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787476092&P2=404&P3=2&P4=VT65yNYyPakpNYLOklLkEEMrYCNjSWez0vCYRJ8Mp%2bgL8YJjqEI1N6hCWIiGhf%2b1g3BGrtAeNdh%2fjbZWIP25Hw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- 23.40.52.85
- 162.159.142.9 US · San Francisco · AS13335 Cloudflare, Inc.
- 20.190.142.164
- 23.11.37.157
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
d874bed90a6f2983825f304a6af1add4166fa7ae63eaf6a56d6a41c4d531162b - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\bb6b2723f595db93c1638e66e7a9708d.png -
d7f2d19e53247bbab998a12787078cb57d6b470a159c4a6b6e9473e9b65d8dd0 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://gettraff.ru/strik?keyword=vcf+file+to+pdf+online
- https://cdn.shopify.com/s/files/1/0483/3751/8752/files/57522001202.pdf
- https://cdn.shopify.com/s/files/1/0481/7718/4925/files/is_a_central_city_a_cbd_oil.pdf
- https://cdn.shopify.com/s/files/1/0439/5044/0603/files/tan_belt_syllabus.pdf
- https://cdn.shopify.com/s/files/1/0432/1237/4174/files/2014_scion_tc_pioneer_radio_manual.pdf
- https://cdn.shopify.com/s/files/1/0438/0708/0608/files/shapes_and_designs_ace_answers_investigation_3.pdf
- http://files.lindastrever.com/uploads/1/3/1/3/131379590/bbff37798c.pdf
- http://files.miguel-castro.com/uploads/1/3/1/6/131606343/d3b8effd00.pdf
- http://files.optimisticliving.com/uploads/1/3/2/7/132710732/97b0cfd27.pdf
- http://files.niangafricanarts.com/uploads/1/3/1/4/131438814/woginerinexinu.pdf
- https://site-1037033.mozfiles.com/files/1037033/kotejenujixopotep.pdf
- https://site-1036629.mozfiles.com/files/1036629/53284977946.pdf
- https://site-1036699.mozfiles.com/files/1036699/21984530369.pdf
- https://site-1038357.mozfiles.com/files/1038357/23296597296.pdf
- http://files.embracebotanicals.com/uploads/1/3/1/3/131378999/sojes_xixetogowemor_lebobedin.pdf
- http://files.ps197qdl.com/uploads/1/3/2/7/132710729/xibekesimebuta_faketekir.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- gettraff.ru
- cdn.shopify.com
- files.lindastrever.com
- files.miguel-castro.com
- files.optimisticliving.com
- files.niangafricanarts.com
- site-1037033.mozfiles.com
- site-1036629.mozfiles.com
- site-1036699.mozfiles.com
- site-1038357.mozfiles.com
- files.embracebotanicals.com
- files.ps197qdl.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 20.42.73.31
- 104.46.162.224
- 162.159.142.9
- 52.110.12.53
- 135.232.92.97
- 135.233.45.221
- 72.145.35.109
- 203.26.79.13
- 104.46.162.231
- 4.230.171.124
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report