MALICIOUS — normal_5f937ed32289d.pdf
MALICIOUS — normal_5f937ed32289d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (80/100). 3 of 50 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
c25a733139f2c49271af2d0b7f5021cff2988f2459bd6a10752e558dd3c41ed1 - SHA-1:
0987c28ad73d9e5ca2fb33f80bea52ba71b320e7 - MD5:
6b62b3b101c064c0e1d38e68ca36bb5b - ssdeep:
1536:XGFxjsUEWIJip69Nw3nIAcC6Is4/t8W6z9FbL0:2FxjsV0CwXzBV8vE - TLSH:
T1D436BEF31493ED8C7A4B97639CAB1986414AD78DA2369B6145CC73ACC4BC67DBE00910 - Submitted as: normal_5f937ed32289d.pdf
- File type: pdf · Size: 63359 bytes
- Verdict: malicious (80/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 80/100 is the fusion of 7 weighted signals:
- Embedded link rated malicious by URL analysis: https://nikoxutaju.weebly.com/uploads/1/3/1/3/131378952/tezesujigebipi.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ttraff.link/123?keyword=radial+drilling+machine+manual+pdf, https://naxedomabaxa.weebly.com/uploads/1/3/1/6/131606472/6432805.pdf, https://vujofuda.weebly.com/uploads/1/3/4/3/134375628/wuduwizinik_depamag_vekakinifudo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 11 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9851 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- searchapp.bundleassets.example
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep(3)._dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
05141452d57d518f6a1acda686745a38979a2e63261ba353c0e5435153b699c7 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\1a725bbf2542f95e01341a822cd89492.png -
a36e44180636445003ee7d1a4dd130f35afc296e072a3e735275611e81bb43c6 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ttraff.link/123?keyword=radial+drilling+machine+manual+pdf
- https://naxedomabaxa.weebly.com/uploads/1/3/1/6/131606472/6432805.pdf
- https://vujofuda.weebly.com/uploads/1/3/4/3/134375628/wuduwizinik_depamag_vekakinifudo.pdf
- https://vewutaniwem.weebly.com/uploads/1/3/0/8/130873717/zesosel.pdf
- https://mabanopovofed.weebly.com/uploads/1/3/1/4/131453130/rixip_wekefuxefuvome_bodoku_telagize.pdf
- https://nikoxutaju.weebly.com/uploads/1/3/1/3/131378952/tezesujigebipi.pdf
- https://uploads.strikinglycdn.com/files/3d8b43d3-928f-4a7c-a564-1bc63f9a39eb/rich_people_problems.pdf
- https://uploads.strikinglycdn.com/files/44517803-e81e-4f84-a656-f80d117e787d/29502890998.pdf
- https://uploads.strikinglycdn.com/files/7bd1d4e8-940d-439d-bda5-7dff65313934/96515693755.pdf
- https://uploads.strikinglycdn.com/files/3c6ac70b-7d2b-4150-abaf-19c439534722/mefogoteganubafovevepep.pdf
- https://uploads.strikinglycdn.com/files/9d225b84-617b-4860-b0d3-0a8d8fd2a3b2/55082523479.pdf
- https://uploads.strikinglycdn.com/files/0d3919d5-c5e2-4882-b3e5-9ef827056fc7/makidupixer.pdf
- https://uploads.strikinglycdn.com/files/2bf69b3f-537e-4a95-b3b3-7a8fcd7d3b72/kurufu.pdf
- https://uploads.strikinglycdn.com/files/3033b980-89b9-4aac-8840-f0805cc3490e/nupalon.pdf
- https://uploads.strikinglycdn.com/files/a170e8c6-75d0-4490-9e9d-bb31aec575cc/audi_allroad_owners_manual.pdf
- https://sewuvemap.weebly.com/uploads/1/3/4/3/134377394/xadamuxupi.pdf
- https://tevumusavobe.weebly.com/uploads/1/3/4/1/134108657/totulojisekol.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/c11f20f6b74.pdf
- https://s3.amazonaws.com/widiku/booklet_layout_design.pdf
- https://s3.amazonaws.com/sazariwapa/cariotipo_humano.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ttraff.link
- naxedomabaxa.weebly.com
- vujofuda.weebly.com
- vewutaniwem.weebly.com
- mabanopovofed.weebly.com
- nikoxutaju.weebly.com
- uploads.strikinglycdn.com
- sewuvemap.weebly.com
- tevumusavobe.weebly.com
- dutitujazekap.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 51.11.192.51
- 20.184.175.9
- 4.150.223.111
- 57.154.63.210
- 20.165.94.63
- 57.155.104.224
- 74.178.232.29
- 172.66.2.5
- 40.103.64.242
- 4.230.171.124
- 149.154.167.99
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report