SUSPICIOUS — normal_5f9943f3009ed.pdf
SUSPICIOUS — normal_5f9943f3009ed.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (68/100). 2 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
ff1d37306e1f3a6b9f7d510218baac6147e68e3bb8fcba20d65bc8581d2b19e2 - SHA-1:
c79a2bf99a228637bbcb242df43039e4bc08cd80 - MD5:
410d0fd1c62b98573cd559665da6ab17 - ssdeep:
1536:lGFD2WVFwP9OPlj+PngD3EqrdshzL+6rkja8Gl4h1:4FDrFwP9Aj+Pw3hdsdzV8GlC - TLSH:
T1EC34BFF351DFDD8C768BAF0369A91469A049D38C613297A4548C3B6CC07C6BD7E60A90 - Submitted as: normal_5f9943f3009ed.pdf
- File type: pdf · Size: 56444 bytes
- Verdict: suspicious (68/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 68/100 is the fusion of 6 weighted signals:
- Contacted 13 external host(s) at runtime (1 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://ttraff.cc/123?keyword=attention+getters+for+speeches+about+yourself, https://uploads.strikinglycdn.com/files/58bd29da-be20-4e2e-946d-92d9cf805fec/mebifugogefazonano.pdf, https://uploads.strikinglycdn.com/files/e75cacc8-ac23-4099-8ef1-4f578c86f611/kagiguruzerawubokaxugo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (10 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9797 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- searchapp.bundleassets.example
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep
- 79.243.254.169.in-addr.arpa
- 255.255.254.169.in-addr.arpa
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
b2f49e58bcfc81e5786f76d4c4250f60c7c0e7c4b0c192ff303eea27db7057d6 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\12dad7b9f33c015df3d919ac99ca07f8.png -
8827508696cf07b4bc7341541f2403cbf46d883efc8d01e2eb4fc81aa0219774 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ttraff.cc/123?keyword=attention+getters+for+speeches+about+yourself
- https://uploads.strikinglycdn.com/files/58bd29da-be20-4e2e-946d-92d9cf805fec/mebifugogefazonano.pdf
- https://s3.amazonaws.com/batoragubukepo/absorbancia_corregida.pdf
- https://uploads.strikinglycdn.com/files/e75cacc8-ac23-4099-8ef1-4f578c86f611/kagiguruzerawubokaxugo.pdf
- https://cdn.shopify.com/s/files/1/0497/3897/3345/files/top_strategy_games_2020_android.pdf
- https://s3.amazonaws.com/biwubeleba/apa_manual_2019.pdf
- https://uploads.strikinglycdn.com/files/bf3dee90-ce03-4db1-ad93-8187c709e5eb/87650795034.pdf
- https://s3.amazonaws.com/luropi/invacare_reliant_450_hoyer_lift_manual.pdf
- https://uploads.strikinglycdn.com/files/aea9a2f2-043b-486c-96cb-65a4777761fc/sukoga.pdf
- https://cdn.shopify.com/s/files/1/0268/7926/2918/files/12251221113.pdf
- https://cdn.shopify.com/s/files/1/0484/8930/0130/files/squirrel_in_armor.pdf
- https://uploads.strikinglycdn.com/files/63eb40d8-de0e-462e-9315-c5f90a0462c2/essential_biochemistry_3rd_edition_s.pdf
- https://cdn.shopify.com/s/files/1/0500/1229/1264/files/desarrollo_sostenible_y_sustentable_diferencia.pdf
- https://uploads.strikinglycdn.com/files/bfafd9c8-3d51-45b6-88c7-8935c05a6bb0/celeste_and_jesse_forever_full_movie.pdf
- https://cdn.shopify.com/s/files/1/0495/2873/3862/files/antz_movie_characters_pictures.pdf
- https://s3.amazonaws.com/mulerux/large_catechism.pdf
- https://uploads.strikinglycdn.com/files/7b912639-8a6e-4b89-8c0d-f264f1280cdd/tuzupagekufisa.pdf
- https://uploads.strikinglycdn.com/files/f1f8b449-047b-4f0b-ad13-c9f1a26ce729/64459166011.pdf
- https://uploads.strikinglycdn.com/files/0dc85038-973e-49df-b559-8d84ce547af9/69458648167.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.cc
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 13.69.109.130
- 4.150.223.96
- 52.123.252.218
- 172.66.2.5
- 52.110.12.52
- 72.154.7.100
- 4.247.188.224
- 4.230.171.124
- 20.112.250.133
- 203.26.79.13
- 135.233.95.135
- 52.230.60.54
- 162.159.36.2
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report