SUSPICIOUS — normal_5f87083de41f5.pdf
SUSPICIOUS — normal_5f87083de41f5.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (50/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c79764d37da31fd1b2f0365437cfbd900c9001a98cba2153b2613ceff9a1660c - SHA-1:
79b72966f3c19717c050571fa7da918156d4c79f - MD5:
7b838aea67b2f59fe39a161178d6e412 - ssdeep:
768:LgGzpD5pzeJcS24UPoQnSoUfgcKzJ45dYNwsVlscmOEjDcIkRAasait:0GF1pyJ32eModYxV9mOgw2asait - TLSH:
T161327CF35067ED4C7AC7AF03AEEB155D9049E3496036EB909888672CC4BCBBC6E10951 - Submitted as: normal_5f87083de41f5.pdf
- File type: pdf · Size: 46552 bytes
- Verdict: suspicious (50/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 50/100 is the fusion of 5 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=slugterra+dark+waters+game+mod+apk, https://uploads.strikinglycdn.com/files/b09f4748-cde5-43d4-94ac-0981090009c7/jamafemovuwazawek.pdf, https://uploads.strikinglycdn.com/files/e8f94ec0-0801-44ef-8330-d898dd94e6b2/33593560088.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: js, uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1019 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- desktop-hsgcbep
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ff02::1:3
- 224.0.0.252
- ff02::1
- 10.240.0.1
- ff02::16
- 10.240.0.255
- 224.0.0.22
- 255.255.255.255
- ff02::1:2
- 224.0.0.251
- ff02::fb
- 239.255.255.250
- 185.125.190.58
- 20.42.179.204 US · Moses Lake · AS8075 Microsoft Corporation
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ggtraff.ru/123?keyword=slugterra+dark+waters+game+mod+apk
- https://uploads.strikinglycdn.com/files/b09f4748-cde5-43d4-94ac-0981090009c7/jamafemovuwazawek.pdf
- https://uploads.strikinglycdn.com/files/e8f94ec0-0801-44ef-8330-d898dd94e6b2/33593560088.pdf
- https://uploads.strikinglycdn.com/files/7f674714-a45b-4457-8a11-685a6cdefcac/79923927964.pdf
- https://uploads.strikinglycdn.com/files/e2620675-209f-4153-b8b0-09f702a91bde/54101206206.pdf
- https://uploads.strikinglycdn.com/files/7a66276e-beb2-4117-9968-641ac5b1bf83/tozok.pdf
- https://uploads.strikinglycdn.com/files/7fddfc13-0a0f-45f3-a169-9292e9825ce8/23445913294.pdf
- https://uploads.strikinglycdn.com/files/c435b526-422e-4105-8e4f-eaa786c2ead0/pepato.pdf
- https://uploads.strikinglycdn.com/files/97785bb4-c671-4269-a578-5cc836ca61c0/terinujofewevezamo.pdf
- https://uploads.strikinglycdn.com/files/6b941b49-f4da-4912-8e63-580962461749/zodirokisajusesakirix.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/fibaxizimudez.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/7304884.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/linurigaruxox.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/vovofofaverun_sawivurovoj_nifawubazox.pdf
- https://uploads.strikinglycdn.com/files/605ae0ed-1aea-406d-bff8-a747c4d3b5af/72229620374.pdf
- https://uploads.strikinglycdn.com/files/64a08551-2bc2-45b0-9772-f353f8442f60/42014494257.pdf
- https://uploads.strikinglycdn.com/files/b4e1449e-2dd2-4757-9663-48b06c97b1cc/26072716738.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f870282c61a3.pdf
- https://cdn-cms.f-static.net/uploads/4365553/normal_5f86f67cc8f29.pdf
- https://cdn-cms.f-static.net/uploads/4365657/normal_5f86f492e4a48.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f870458bbffa.pdf
- https://cdn.shopify.com/s/files/1/0436/2780/6883/files/natural_capital_investment_fund.pdf
- https://cdn.shopify.com/s/files/1/0482/8764/5851/files/tusizotopabojukugoko.pdf
- https://cdn.shopify.com/s/files/1/0463/5639/8246/files/kojulutawivan.pdf
- https://cdn.shopify.com/s/files/1/0500/9752/0801/files/dabefelaba.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- jakedekokobara.weebly.com
- genigudepa.weebly.com
- fijojonibiw.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 20.42.179.204
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report