SUSPICIOUS — normal_5f9269fdc4b0c.pdf
SUSPICIOUS — normal_5f9269fdc4b0c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (64/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fed44184aa30bb53aace11e62b32d0a9b0a8d4ce1dd6b4d4fce62d0387c882de - SHA-1:
8903037d4b1d579dd126b9e64e54296411f9e8ef - MD5:
fd6472def577ffd91f2a8d7672416f53 - ssdeep:
3072:gFBeJ3Ha3f7z9Ii6ryBvrVNO0Fyh8xDM:YYJK3f3b6rWzTIj - TLSH:
T1F13ADFF30197DD4D27C6EB63ADF61968518A8F485123DA6485C87A2CC4BCB7E7F01A10 - Submitted as: normal_5f9269fdc4b0c.pdf
- File type: pdf · Size: 98576 bytes
- Verdict: suspicious (64/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 64/100 is the fusion of 5 weighted signals:
- Contacted 16 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/123?keyword=opinion+article+example+pdf, https://cdn.shopify.com/s/files/1/0437/8204/5858/files/u_substitution_practice_worksheet_with_answers.pdf, https://cdn.shopify.com/s/files/1/0482/8361/5394/files/10917087872.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (8 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9749 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- desktop-hsgcbep
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\6f5806a845ee3b9c1b6f6d8624099068.png -
d559c308ab05d00a57ada1a88f561cb8d45ee733ff4e885429b8ce54c3455159 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
b37cfaabd726f694ce9025c5db8066d060588ccb3fe443db2cfb328930aa6768 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://gettraff.ru/123?keyword=opinion+article+example+pdf
- https://cdn.shopify.com/s/files/1/0437/8204/5858/files/u_substitution_practice_worksheet_with_answers.pdf
- https://cdn.shopify.com/s/files/1/0482/8361/5394/files/10917087872.pdf
- https://cdn.shopify.com/s/files/1/0491/8168/7974/files/descargar_sonic_cd_para_android_apk_full.pdf
- https://cdn.shopify.com/s/files/1/0428/3564/0487/files/wow_fishing_buddy_guide.pdf
- https://cdn-cms.f-static.net/uploads/4372105/normal_5f8e72f127001.pdf
- https://cdn-cms.f-static.net/uploads/4392854/normal_5f8fe5eeeb61d.pdf
- https://uploads.strikinglycdn.com/files/2354041c-5ef2-4014-9840-7b09a85f0572/dexibazorawasiwo.pdf
- https://uploads.strikinglycdn.com/files/5f5c7ce4-76aa-4526-a131-cf1f9ffd3811/37371464833.pdf
- https://uploads.strikinglycdn.com/files/c6bc0b12-aac5-4007-8228-45b123bf365d/58432927315.pdf
- https://uploads.strikinglycdn.com/files/1b6d7dfe-101f-4a73-ad4b-78636a8b0b1a/89968541070.pdf
- https://uploads.strikinglycdn.com/files/98dbf630-e42c-4975-866b-57fe9ec93307/24199838295.pdf
- https://jemajodelevo.weebly.com/uploads/1/3/4/3/134394711/setojavodofik_fiwikekabuvolu.pdf
- https://birebojutadavom.weebly.com/uploads/1/3/4/3/134342015/8166129.pdf
- https://xilorufanil.weebly.com/uploads/1/3/0/7/130739938/widef-xilajuzet-wisogafit.pdf
- https://s3.amazonaws.com/ganubatebedoxez/21318530355.pdf
- https://s3.amazonaws.com/wuzalugiseto/brayton_cycle_process.pdf
- https://s3.amazonaws.com/fapaga/business_plan_boutique_hotel.pdf
- https://s3.amazonaws.com/tugumeb/3984018813.pdf
- https://s3.amazonaws.com/wonoti/63598712004.pdf
- https://cdn-cms.f-static.net/uploads/4374380/normal_5f8e8ec391aea.pdf
- https://cdn-cms.f-static.net/uploads/4366305/normal_5f872b822c684.pdf
- https://cdn-cms.f-static.net/uploads/4371787/normal_5f8bffe6a1a5f.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- jemajodelevo.weebly.com
- birebojutadavom.weebly.com
- xilorufanil.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 13.69.116.105
- 40.79.163.154
- 20.247.185.124
- 52.110.12.16
- 172.215.188.225
- 4.230.171.124
- 135.233.95.144
- 4.150.223.103
- 52.123.129.14
- 40.99.134.2
- 135.232.92.137
- 172.178.240.162
- 203.26.79.13
- 92.223.78.30
- 51.132.193.104
- 48.199.12.1
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report