MALICIOUS — normal_606099f402861.pdf
MALICIOUS — normal_606099f402861.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
e12d8dc549677574b330a8042912c074341b194527f7bcae68e62d30d10083b0 - SHA-1:
296cd5d9f9a5ccbfb50d758f22c3e33bd45e9de8 - MD5:
ad391274917b4f86d5d1883d3dbfcbc3 - ssdeep:
1536:bnXpghypKaqpNggKh8Sld9Bq2HM5MXl9w9U6vNIGh1Wo3OLWSNL:rXp6znpN12d9oZ5C9QU6vKG1n30Wm - TLSH:
T10339E1F35587CD8CB69B6B43A9AB2524648DE78C7031EA7104C8AA3C957C2BD7C11A20 - Submitted as: normal_606099f402861.pdf
- File type: pdf · Size: 87398 bytes
- Verdict: malicious (98/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!AD391274917B
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/565cd659-e374-48bf-aa3e-08d11f4c481b/keurig_model_k40_manual.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 21 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://kuzutuzo.ru/123?utm_term=bhaskar+oru+rascal+film+songs, https://uploads.strikinglycdn.com/files/565cd659-e374-48bf-aa3e-08d11f4c481b/keurig_model_k40_manual.pdf, https://uploads.strikinglycdn.com/files/508add6b-c6f9-4a70-8022-d27d3a3b35cc/jorasonuxowilaxasova.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9850 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep
- ntp.ubuntu.com
- 255.255.254.169.in-addr.arpa
- 79.243.254.169.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\7b84e8da6b191fa8e9dd7581565a8bb7.png -
f0c45f6f9555d370f7e66ef5ba1970258f2d5cc1ba3d87e9ad5efbd02d42a444 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
ff35237e66b48e5bfb0b20eb2033763782df3f9411ee732ad18493f150f849d9 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://kuzutuzo.ru/123?utm_term=bhaskar+oru+rascal+film+songs
- https://uploads.strikinglycdn.com/files/565cd659-e374-48bf-aa3e-08d11f4c481b/keurig_model_k40_manual.pdf
- https://uploads.strikinglycdn.com/files/508add6b-c6f9-4a70-8022-d27d3a3b35cc/jorasonuxowilaxasova.pdf
- https://e8677ced-6330-435e-8237-200fb10408a4.filesusr.com/ugd/a4c1fa_0271eb2ee9134451bd16812545e31fce.pdf?index=true
- http://ingmijn.com/30731674182pufbg.pdf
- https://5a98ae10-8c7e-48da-b83f-9bcbc644cfa3.filesusr.com/ugd/9a8764_c648f0922dd04af39f52924037b56b52.pdf?index=true
- https://cdn.sqhk.co/tumowara/gfiijai/racing_car_3d_mod_apk.pdf
- https://uploads.strikinglycdn.com/files/b6da561b-66c4-4113-b97a-771d360e4779/76280322312.pdf
- https://52cfbdcc-51c1-4e85-ba83-ad74149b4620.filesusr.com/ugd/93d431_2aa3996bab3a4644a669307f76bb93a5.pdf?index=true
- https://mimudokax.weebly.com/uploads/1/3/4/7/134742140/3fe4018e.pdf
- https://cdn.sqhk.co/pujapipiwat/5NhiFbC/happy_wheels_2010_download.pdf
- http://shopsupergood.site/how_do_you_clear_a_canon_ink_absorberwwxqt.pdf
- https://gugajonegil.weebly.com/uploads/1/3/0/8/130813642/faxazekut.pdf
- https://0503187d-52cd-4237-9521-a3cb9bf551ae.filesusr.com/ugd/5bb01c_7a2224cd9a974333ba5d3fab6f9fef98.pdf?index=true
- https://uploads.strikinglycdn.com/files/c53f8c86-2ab6-4b5f-a5d4-ecb37e8aaf9b/liwepitegitapifego.pdf
- https://050a9d39-d8a1-4107-8be8-b2b70b72e454.filesusr.com/ugd/5262df_b1e5d52f0deb4a8684439343ae3f5f10.pdf?index=true
- https://34e2f0dc-0077-42bd-a047-efa2502e92af.filesusr.com/ugd/8a05ec_952c25d2be664f11b79613074815e44c.pdf?index=true
- http://meetdouche.xyz/30410377468gt30c.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- kuzutuzo.ru
- uploads.strikinglycdn.com
- e8677ced-6330-435e-8237-200fb10408a4.filesusr.com
- ingmijn.com
- 5a98ae10-8c7e-48da-b83f-9bcbc644cfa3.filesusr.com
- cdn.sqhk.co
- 52cfbdcc-51c1-4e85-ba83-ad74149b4620.filesusr.com
- mimudokax.weebly.com
- shopsupergood.site
- gugajonegil.weebly.com
- 0503187d-52cd-4237-9521-a3cb9bf551ae.filesusr.com
- 050a9d39-d8a1-4107-8be8-b2b70b72e454.filesusr.com
- 34e2f0dc-0077-42bd-a047-efa2502e92af.filesusr.com
- meetdouche.xyz
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.123.252.246
- 40.79.167.10
- 85.210.196.11
- 172.172.255.217
- 135.233.95.80
- 74.179.77.204
- 52.110.12.16
- 4.230.171.124
- 57.154.63.210
- 4.155.95.136
- 74.178.76.54
- 135.232.92.137
- 20.42.65.90
- 52.123.128.14
- 74.179.71.159
- 57.155.101.212
- 203.26.79.13
- 135.233.45.221
- 52.123.252.222
- 20.184.175.22
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report