MALICIOUS — votegakowukeb.pdf
MALICIOUS — votegakowukeb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
0449812e36945bb8799ba712415c887ef75c6c6a176714c57b7be2eb39a1f8b9 - SHA-1:
7ce6bb716e3b0545a8dba6c074a88c2b7b065375 - MD5:
d0f2342242eb8fadc115ce8ece8a32b1 - ssdeep:
1536:3NOMb6DUeMCbQopg+A71gY2f/D7PosLQxe426ahr+fdN6WkNpOPaWcWdthn6fO9u:Zb6DUzoyF0DToskQ7LS/PCwefO9MP - TLSH:
T1763AE1F361E7DCCC7A658F4399BA106CE48AD3981132D5514189F6AC80FC6BFBE04A51 - Submitted as: votegakowukeb.pdf
- File type: pdf · Size: 97949 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 14 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://dentinale.eu/wp-content/plugins/super-forms/uploads/php/files/3e2eeaa4c536bfa1e5325508db6073f9/fubuzezuxase.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://amezdigital.com/wp-content/plugins/super-forms/uploads/php/files/15568fa1aa4e3e8a39aa7250acf85e33/nometifajamoganog.pdf, https://ecef-groupe.com/wp-content/plugins/super-forms/uploads/php/files/s7e1h0o7ogommh4qicblp331b3/tuzedujis.pdf, http://1utilaje.ro/mm/file/56397693142.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9845 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787778461&P2=404&P3=2&P4=BXXQJ%2fa%2b9odnLlsFiYoH8BE%2bHXATCR9mDi2P%2fO%2f7g%2bABuS3hJaTe1YfE%2bBeXr8lbuVy3Tjuj89mzlDEe9Dt4hg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787778529&P2=404&P3=2&P4=lOzi60ORMQsD6onR8y1%2f2wQ%2bFgjSJLEs10ddr3N0b8Ad%2bBgCjUAzlGaQz02vq2xsBz4pm0wLy%2bjsGV45rHfoiA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787175229&P2=404&P3=2&P4=hDyYMOwQhVHhQMqQGknz04DAzu1coGqloUxlafy%2fb4NChEmP6ISLsL9mOjpjDUovBxN72ZDWsRhaceh7moERBA%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\04d65dc79b86265ef84da61f7eb6fa91.png -
86aaf5fdfc48d3ce4fe892498c1865e48ddcff675badafa840471f225ed72900 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
438f19dad19730054459e00f568de632b3629708cbe0a0e9270a8bbc7fb2f692 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/LPIa9PGmDLg/uplcv?utm_term=what+does+onion+eyed+mean+in+shakespeare
- https://amezdigital.com/wp-content/plugins/super-forms/uploads/php/files/15568fa1aa4e3e8a39aa7250acf85e33/nometifajamoganog.pdf
- https://ecef-groupe.com/wp-content/plugins/super-forms/uploads/php/files/s7e1h0o7ogommh4qicblp331b3/tuzedujis.pdf
- http://1utilaje.ro/mm/file/56397693142.pdf
- https://www.perfumista.co.uk/wp-content/plugins/super-forms/uploads/php/files/ff1d3e7ed34528f262a0f98f06cab9c8/51512167528.pdf
- https://dentinale.eu/wp-content/plugins/super-forms/uploads/php/files/3e2eeaa4c536bfa1e5325508db6073f9/fubuzezuxase.pdf
- http://for-rent-antwerp.com/wp-content/plugins/formcraft/file-upload/server/content/files/160838d5ec2d8c---5376239533.pdf
- http://www.naturapreserved.com/wp-content/plugins/formcraft/file-upload/server/content/files/16072ba8d5e492---44116372537.pdf
- http://koreaseowon.com/ckupload/files/remitimewaseluwuse.pdf
- http://nacnsuaa.com/clients/4/49/49ab1acc6c62b5a39110d621a19f71c0/File/58204415304.pdf
- http://anhbanglaw.com/userfiles/file/25633109057.pdf
- https://divorcioconsensual.com.br/wp-content/plugins/super-forms/uploads/php/files/e788bf7b5a94b046037347ed94146d1d/63245506392.pdf
- http://vudafrique.com/wp-content/plugins/super-forms/uploads/php/files/b8c778e23b5974f3ce30a23116e2d19d/19485841212.pdf
- http://www.etoiles-recrutement.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609a3720a2e8b---52651803381.pdf
- https://k9-warrior.com/wp-content/plugins/super-forms/uploads/php/files/52fjhod75p38hhaiqotbpqsp81/40879333887.pdf
- http://palazzodiaz.com/userfiles/files/14518567908.pdf
- http://www.kreasoft.mx/wp-content/plugins/formcraft/file-upload/server/content/files/160b8e2815755d---91129497263.pdf
- http://104.156.58.56/~web2inbox/wp-content/plugins/formcraft/file-upload/server/content/files/16094287ce8016---kewep.pdf
- http://mobilephleb.com/clients/2/2d/2d2188d13063160162e6e2bbcdac547d/File/buzojojibeponatol.pdf
- https://www.darrellstuckey.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b1f687bc527---nedidirefevu.pdf
- http://promador.pl/userfiles/file/vosuwikuzo.pdf
- http://expertcomptablecourreges.fr/michel_courreges/userfiles/file/71071838526.pdf
- https://earthideasawnings.com/wp-content/plugins/formcraft/file-upload/server/content/files/16078787bd88d4---5862940069.pdf
- https://gemwares.com/userfiles/file/98226324608.pdf
- http://doks-films.com/pcms/content/file/xugivumadi.pdf
Embedded domains
- feedproxy.google.com
- amezdigital.com
- ecef-groupe.com
- www.perfumista.co.uk
- dentinale.eu
- for-rent-antwerp.com
- www.naturapreserved.com
- koreaseowon.com
- nacnsuaa.com
- anhbanglaw.com
- divorcioconsensual.com.br
- vudafrique.com
- www.etoiles-recrutement.com
- k9-warrior.com
- palazzodiaz.com
- www.kreasoft.mx
- mobilephleb.com
- www.darrellstuckey.com
- promador.pl
- expertcomptablecourreges.fr
- earthideasawnings.com
- gemwares.com
- doks-films.com
- www.w3.org
- purl.org
Embedded IP addresses
- 104.156.58.56
- 52.110.12.14
- 52.110.12.48
- 4.230.171.124
- 20.247.184.142
- 203.26.79.13
- 4.207.44.70
- 20.112.250.133
- 52.123.129.14
- 74.178.76.128
- 4.150.223.104
- 135.233.95.80
- 48.211.4.16
- 135.233.45.223
- 4.150.223.110
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report