MALICIOUS — 0424f38f80589d5d8b317f348d5d1fb5bac6fd2ee8b847029650b511c510f5d5
MALICIOUS — 0424f38f80589d5d8b317f348d5d1fb5bac6fd2ee8b847029650b511c510f5d5 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
0424f38f80589d5d8b317f348d5d1fb5bac6fd2ee8b847029650b511c510f5d5 - SHA-1:
30df8db9595f3e08cd92940503d70d695102c3b0 - MD5:
f319cb4dfb6ec3f33626e5b81a1521b9 - ssdeep:
1536:33Rh1AU/c1OyFN/e7xlJX5A/wSMWsjWypOlWWxhcnfMQOGJbkGZ:nRh5mOyFNG7XdAZMqlDhcndOGVB - TLSH:
T12337C0F361A7DE8CB78ADFC366EB45A85046E38C1132DBD00588B66C897C5BDBE14940 - Submitted as: 0424f38f80589d5d8b317f348d5d1fb5bac6fd2ee8b847029650b511c510f5d5
- File type: pdf · Size: 70769 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://www.frontiermea.com/sites/all/libraries/ckfinder/userfiles/files/maxinebokot.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 15 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://huntic.ru/uplcv?utm_term=what+was+lincoln%27s+plan+of+reconstruction, http://epodhajska.eu/UserFiles/File/26059539027.pdf, https://tcufroghouses.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612f923711142---ketukevawanojilagupezege.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9653 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- WORK
- work
- work.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
505a3517378f38ac763900dbcd0e6355c268cde21b52b2eec231236ba2c28922 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\da645fd19fd6e61819ec8f5c622eb33c.png -
0d2b5be9dbb741074d91e1f4566d0aa625e710c9da7915426b1d2cf0e18c8aaa - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://huntic.ru/uplcv?utm_term=what+was+lincoln%27s+plan+of+reconstruction
- http://epodhajska.eu/UserFiles/File/26059539027.pdf
- https://tcufroghouses.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612f923711142---ketukevawanojilagupezege.pdf
- http://www.majoriscambio.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1613865ea7b9b9---vusuvukebuzija.pdf
- https://ksboutlet.com/file/files/88990018945.pdf
- https://anitacalderon.com/ckfinder/userfiles/files/xamepibujeluk.pdf
- https://www.frontiermea.com/sites/all/libraries/ckfinder/userfiles/files/maxinebokot.pdf
- https://techielingo.com/fck_uploads/files/59133851422.pdf
- https://sammycar.ch/sammy/sites/default/sammyfiles/newsletterfile/ralonerozizadixizerid.pdf
- http://24x7taazasamachar.com/assets/ckfinder/core/connector/php/uploads/files/darinididawegegab.pdf
- http://gevenschoenen.nl/ckfinder/userfiles/files/nerubewuxa.pdf
- http://tjsyjdq.com/v15/Upload/file/202197718258023.pdf
- https://texigo.tw/upfile/files/2021/09/19/60619416189.pdf
- https://livermore.com/wysiwygfiles/file/48659276773.pdf
- http://35ju.21tg.cn/uploadfile/ckeditor/files/jegipidipekopadonefuxoz.pdf
- https://processwork.archerhuang.com/ConImg/files/navaroluf.pdf
- http://abc-tel.ru/data/File/rixinexazubijaburo.pdf
- http://www.teaterskolen-efteruddannelsen.dk/ckfinder/userfiles/files/15654537155.pdf
- http://giorgimpianti.com/userfiles/file/47849631297.pdf
- http://www.impactit.in/ckfinder/userfiles/files/jawexezewilinidetal.pdf
- http://evo-models.com/uploads/userfiles/files/gupinamajedolofuto.pdf
- http://churchliferesources.org/wp-content/plugins/formcraft/file-upload/server/content/files/1613bc4660a18b---72735337440.pdf
- http://teaterskolen-efteruddannelsen.dk/ckfinder/userfiles/files/madifelirov.pdf
- http://smsalumni1971.com/apadmin/uploads/userfiles/files/89345407570.pdf
- https://ichapps.peaceofworld.com/ichapps/ckeditor-ckfinder-integration/uploads/files/70364015449.pdf
Embedded domains
- huntic.ru
- epodhajska.eu
- tcufroghouses.com
- www.majoriscambio.com.br
- ksboutlet.com
- anitacalderon.com
- www.frontiermea.com
- techielingo.com
- sammycar.ch
- 24x7taazasamachar.com
- gevenschoenen.nl
- tjsyjdq.com
- texigo.tw
- livermore.com
- 35ju.21tg.cn
- processwork.archerhuang.com
- abc-tel.ru
- giorgimpianti.com
- www.impactit.in
- evo-models.com
- churchliferesources.org
- smsalumni1971.com
- ichapps.peaceofworld.com
- www.w3.org
- purl.org
Embedded IP addresses
- 4.150.223.112
- 52.110.12.14
- 4.230.171.124
- 52.253.84.76
- 85.210.196.11
- 20.165.94.63
- 74.178.240.51
- 20.112.250.133
- 52.123.129.14
- 135.234.160.245
- 74.178.76.44
- 203.26.79.13
- 52.168.117.170
- 4.207.44.72
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report