MALICIOUS — normal_5f8b6ec75e45f.pdf
MALICIOUS — normal_5f8b6ec75e45f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
cd4e4b0ab8d8c392a79487bd884427f4e95e176be3a8474eeb2d2d0d2ced1acb - SHA-1:
ac36fa8e3a1e452f7cc8a0853a842a8cc226eaf9 - MD5:
5d3d581980ca8e56ab9b592590eeb39b - ssdeep:
1536:jGFoeaBJF5BNQO1/OHM41HwZBLxQORWJ/WqtDGI1yW:yFoe475TQC/m1HwpQOYJ9DGIh - TLSH:
T1E1359EF300A7ED4C7B8BAF43ADB71059754AD6887127AB901448672CC4BC9BD7F11A41 - Submitted as: normal_5f8b6ec75e45f.pdf
- File type: pdf · Size: 59748 bytes
- Verdict: malicious (72/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 72/100 is the fusion of 6 weighted signals:
- Contacted 19 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/aec44298-bcc6-40b6-95a4-eb43fe9f69fe/89171552909.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.link/123?keyword=cardfight+vanguard+online+apk, https://uploads.strikinglycdn.com/files/aec44298-bcc6-40b6-95a4-eb43fe9f69fe/89171552909.pdf, https://uploads.strikinglycdn.com/files/dbc5bcc4-5178-4300-87ba-3f248a9b1789/jedobinaj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (11 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9686 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- _dosvc._tcp.local
- ntp.ubuntu.com
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
ca39683abc186ff919ffd5116f2430eca351bcfd57ab4b305d182093ceda9e51 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\66f6453c53613fed4673d1d8758ce0ae.png -
2073f35e1727cd6dbe56dfb648df7724f0cadcef92dbbfac51b3211ea1a9f79f - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ttraff.link/123?keyword=cardfight+vanguard+online+apk
- https://uploads.strikinglycdn.com/files/aec44298-bcc6-40b6-95a4-eb43fe9f69fe/89171552909.pdf
- https://uploads.strikinglycdn.com/files/dbc5bcc4-5178-4300-87ba-3f248a9b1789/jedobinaj.pdf
- https://uploads.strikinglycdn.com/files/2da09c95-d59b-4b67-b5b4-2d2abfc9ffc7/kukekajowivoraj.pdf
- https://uploads.strikinglycdn.com/files/3a5e6d15-9164-4c83-a682-8fc9fe4eff5f/10175332935.pdf
- https://uploads.strikinglycdn.com/files/a91636d0-24cf-4e4a-b8f1-bf31e6d2c075/timulonogivoluxux.pdf
- https://cdn-cms.f-static.net/uploads/4370317/normal_5f894c023018a.pdf
- https://cdn-cms.f-static.net/uploads/4369522/normal_5f8b5597a3380.pdf
- https://cdn-cms.f-static.net/uploads/4367687/normal_5f8b5e19d6bf5.pdf
- https://cdn-cms.f-static.net/uploads/4366400/normal_5f8b5d7827bda.pdf
- https://cdn-cms.f-static.net/uploads/4367938/normal_5f8973150992d.pdf
- https://cdn.shopify.com/s/files/1/0435/0056/8736/files/nananas_buried_treasure_episode_1.pdf
- https://cdn.shopify.com/s/files/1/0481/0509/5331/files/95383561915.pdf
- https://cdn.shopify.com/s/files/1/0499/8456/9494/files/revere_ware_tea_kettle_replacement_parts.pdf
- https://cdn.shopify.com/s/files/1/0483/9908/9824/files/jeruruxakutexu.pdf
- https://degujipimisa.weebly.com/uploads/1/3/1/4/131453395/zexenifeni.pdf
- https://rakamukomegu.weebly.com/uploads/1/3/2/6/132681656/20069.pdf
- https://cdn.shopify.com/s/files/1/0497/1518/3777/files/pijawigikegujiluvuxaxijep.pdf
- https://cdn.shopify.com/s/files/1/0482/5042/1410/files/64669544099.pdf
- https://cdn.shopify.com/s/files/1/0440/7777/7061/files/how_to_upload_image_using_retrofit_android.pdf
- https://cdn.shopify.com/s/files/1/0482/1070/6619/files/91806801787.pdf
- https://uploads.strikinglycdn.com/files/81cb2735-4eb8-4e7e-ab41-f790579ce1ea/52528035824.pdf
- https://uploads.strikinglycdn.com/files/7af3bb5a-a56b-4236-9c75-1af4596baf63/bestself_co._the_self_journal.pdf
- https://uploads.strikinglycdn.com/files/97cda096-7668-4497-badb-8f7dccddeb97/24171566542.pdf
- https://uploads.strikinglycdn.com/files/f53f900a-dd86-45d1-904b-ea13d579ac37/geboxorobimowavodukasalum.pdf
Embedded domains
- ttraff.link
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- degujipimisa.weebly.com
- rakamukomegu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.168.117.174
- 52.168.112.67
- 72.153.5.133
- 203.26.79.13
- 40.79.141.155
- 20.42.179.192
- 20.247.184.142
- 85.210.193.152
- 4.230.171.124
- 74.178.240.61
- 74.178.76.54
- 52.123.128.14
- 40.99.134.2
- 40.103.64.242
- 52.123.252.220
- 52.123.252.195
- 20.42.65.90
- 4.209.250.170
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report