MALICIOUS — normal_5f8edad960430.pdf
MALICIOUS — normal_5f8edad960430.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (84/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
ee8e2e28e80ed9dc0f364c26d57210e39c53487671a109b3bacc4cabccf74acb - SHA-1:
abe3cbc5428b62e9568b6cdb79c22c83e1eb408b - MD5:
a0da74a1ea717807fc60e9671992ab59 - ssdeep:
768:dgGzpDUpSq7yF8haHQFYT6gQSPhzGk9CPjZ0UidWLnztkUg18seIvwwuUJ9Ju6d8:eGFgp8Pha0yo+ztkUg18seMqUJ9RsY2r - TLSH:
T18A329DF350A7DD8C7ACBAB077DEA2168904D96486072E790499C7B2CC4BC6BC7E50960 - Submitted as: normal_5f8edad960430.pdf
- File type: pdf · Size: 47465 bytes
- Verdict: malicious (84/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 84/100 is the fusion of 6 weighted signals:
- Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/49b4f926-bbb1-44bd-88bb-35606db0eb3b/54365989100.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 12 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://ttraff.club/123?keyword=cafeteria+nipponica+apk+unlimited+money, https://cdn-cms.f-static.net/uploads/4378599/normal_5f8dbde66a073.pdf, https://cdn-cms.f-static.net/uploads/4369499/normal_5f8bc2224cb36.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9853 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- 252.0.0.224.in-addr.arpa
- 255.255.254.169.in-addr.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 79.243.254.169.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\5f4bf973e866a85721b131610f712a0e.png -
9d265e21a50184f1517368e6b598d4c963ac424f99ec460a934a40881abe9200 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
711e0936c35496161218ae79affa50b1cc0441dcd50c2d39a421f1f5ebc37cf6 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ttraff.club/123?keyword=cafeteria+nipponica+apk+unlimited+money
- https://cdn-cms.f-static.net/uploads/4378599/normal_5f8dbde66a073.pdf
- https://cdn-cms.f-static.net/uploads/4369499/normal_5f8bc2224cb36.pdf
- https://cdn-cms.f-static.net/uploads/4370089/normal_5f890658172ef.pdf
- https://cdn-cms.f-static.net/uploads/4366381/normal_5f8998e48bd0d.pdf
- https://cdn-cms.f-static.net/uploads/4366347/normal_5f87aafa9b8f5.pdf
- https://cdn-cms.f-static.net/uploads/4372105/normal_5f8e34689d734.pdf
- https://cdn-cms.f-static.net/uploads/4373999/normal_5f8a6ab28f69c.pdf
- https://cdn.shopify.com/s/files/1/0434/5069/5841/files/guxiparitisedagok.pdf
- https://cdn.shopify.com/s/files/1/0430/3467/3301/files/modelos_de_frisos_cronologicos.pdf
- https://cdn.shopify.com/s/files/1/0504/3398/2618/files/zaffaroni_libros_gratis.pdf
- https://cdn.shopify.com/s/files/1/0480/7481/7693/files/pekanibipiniwomagizo.pdf
- https://uploads.strikinglycdn.com/files/49b4f926-bbb1-44bd-88bb-35606db0eb3b/54365989100.pdf
- https://uploads.strikinglycdn.com/files/8d8c484f-97f5-438b-9836-9d794a89594e/69389997401.pdf
- https://uploads.strikinglycdn.com/files/06875d61-8cb3-42eb-a24d-1e2672632500/tilebafit.pdf
- https://uploads.strikinglycdn.com/files/d34ddf54-e1a4-4c26-8794-ba1cbbfcc00f/43145004014.pdf
- https://uploads.strikinglycdn.com/files/878116b5-f82d-4eae-8508-0798f15175a5/44651245651.pdf
- https://uploads.strikinglycdn.com/files/d0f7201f-ebda-411d-95d2-d126645963f3/gikajoro.pdf
- https://uploads.strikinglycdn.com/files/71cfdd67-84c9-49c3-9037-2f44f4bf3b43/26593308182.pdf
- https://uploads.strikinglycdn.com/files/86d06ee0-a7a2-4660-a5cf-651ab486d75f/24728536878.pdf
- https://uploads.strikinglycdn.com/files/213f4229-aeef-427d-9600-fa7234e6f0d2/78345277022.pdf
- https://uploads.strikinglycdn.com/files/337ea922-c2c2-4ee5-93d2-df6934df2119/maselatu.pdf
- https://uploads.strikinglycdn.com/files/f65e2dc1-fee6-4d0c-b80b-834f773d3c19/taxeteru.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ttraff.club
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.123.252.223
- 40.84.85.40
- 4.230.171.124
- 203.26.79.13
- 20.165.94.63
- 135.232.92.97
- 20.76.201.171
- 52.123.128.14
- 74.178.232.29
- 135.233.45.223
- 92.223.78.30
- 4.150.223.110
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report