SUSPICIOUS — purpose_driven_life_free_ebook.pdf
SUSPICIOUS — purpose_driven_life_free_ebook.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (56/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
e66d17538053839d82fa21abf05c0e12bbf2fab669c42f63d1edc3c3d2d59dde - SHA-1:
1e074b882b532a11077d512527efacf10189ea9f - MD5:
c7f5a6a630dbcb92528a9342327a67fc - ssdeep:
768:SgGzpD+pP/ijfBZLQHtQDOz5go/8P39rWbNDzkjT3RHW38EupGscJ0Jx:PGFCpPYfPsbNUf8scJ0Jx - TLSH:
T1DA307DF71097EC8C7B8B6B07AEAB0169508AD78D6137D3E10588372CD47CAED6E10960 - Submitted as: purpose_driven_life_free_ebook.pdf
- File type: pdf · Size: 38217 bytes
- Verdict: suspicious (56/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 56/100 is the fusion of 6 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=purpose+driven+life+free+ebook, https://cdn-cms.f-static.net/uploads/4375908/normal_5f8aa6db1f67f.pdf, https://cdn-cms.f-static.net/uploads/4382772/normal_5f8b9494739d4.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 10 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9633 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- searchapp.bundleassets.example
- inference.location.live.net
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- 255.255.254.169.in-addr.arpa
- 251.0.0.224.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\962faedaceaaa48cefea5c6b061e3508.png -
9f82b125ccb45f6c3a1a6a7541b83687c1fe322b72f3d68af413c29cf9215e0d - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
dad5bcc1d18c534f48873d714726370bd86048e1c2972f280a8a4554edae49ca - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://cctraff.ru/strik?keyword=purpose+driven+life+free+ebook
- https://s3.amazonaws.com/pazifetanegapu/what_is_anti_social_behaviour.pdf
- https://s3.amazonaws.com/lewuli/zagimapob.pdf
- https://s3.amazonaws.com/luramamelolem/87112968153.pdf
- https://s3.amazonaws.com/subud/49780298551.pdf
- https://cdn-cms.f-static.net/uploads/4375908/normal_5f8aa6db1f67f.pdf
- https://cdn-cms.f-static.net/uploads/4382772/normal_5f8b9494739d4.pdf
- https://cdn-cms.f-static.net/uploads/4392215/normal_5f90a9d29381d.pdf
- https://cdn-cms.f-static.net/uploads/4367640/normal_5f8eab599939f.pdf
- https://cdn.shopify.com/s/files/1/0503/7214/9416/files/voltix_power_failure_led_light_bulb_instructions.pdf
- https://cdn.shopify.com/s/files/1/0481/2619/7923/files/rutalefejuxobimaw.pdf
- https://uploads.strikinglycdn.com/files/3f204c26-5279-4854-b65f-f8944510d9f4/duramegoxutefi.pdf
- https://uploads.strikinglycdn.com/files/5f4cdaf7-ebb2-47c0-ae7d-688511f4bd8a/surinuruk.pdf
- https://uploads.strikinglycdn.com/files/2893b47b-797d-4b43-93ca-f5874314c408/80096870087.pdf
- https://uploads.strikinglycdn.com/files/153d2420-42b2-4d76-a99a-eb5d65ed512c/49554414365.pdf
- https://uploads.strikinglycdn.com/files/68a09517-d28d-4e90-8902-90e675e83fd5/37096575134.pdf
- https://cdn.shopify.com/s/files/1/0497/2720/9629/files/words_with_q_and_hay.pdf
- https://cdn.shopify.com/s/files/1/0484/8926/7362/files/pogipipe.pdf
- https://cdn.shopify.com/s/files/1/0497/5139/2420/files/15152591325.pdf
- https://cdn.shopify.com/s/files/1/0502/6293/3704/files/caucasian_chalk_circle_summary.pdf
- https://uploads.strikinglycdn.com/files/ef2d9e9b-4097-483e-84db-be71666ed6da/google_developer_android_training.pdf
- https://uploads.strikinglycdn.com/files/08d316f3-a275-406f-865c-32f2511b53da/kogox.pdf
- https://uploads.strikinglycdn.com/files/19713a96-d9dc-4bf2-a8e7-dafe0b0aa831/30374113068.pdf
- https://uploads.strikinglycdn.com/files/2331b5e0-db3e-4d2d-9454-6cf288a06284/12479779829.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 162.159.142.9
- 52.168.117.174
- 52.230.60.54
- 135.233.95.144
- 52.110.12.11
- 20.42.179.192
- 13.89.179.12
- 52.123.129.14
- 162.159.36.2
- 4.230.171.124
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report