MALICIOUS — 0482ff32c8832ce67e0656c4a2521594d5759fc78fbb85475028767700b28ba0
MALICIOUS — 0482ff32c8832ce67e0656c4a2521594d5759fc78fbb85475028767700b28ba0 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
0482ff32c8832ce67e0656c4a2521594d5759fc78fbb85475028767700b28ba0 - SHA-1:
91dc4eaa2256df7c33c43cf8c4112b3503e61e8e - MD5:
115994f9e4db55a55755f92130d598fc - ssdeep:
1536:f883225IGZ0F4GZyLBEMp0VPTYs4Hh0h67C0WSOAkNkXRYN1jvWQbZt2rQ1RO:xGSz9imC7VPTb4B00+9RNkhw7WQD2rQW - TLSH:
T1A139D0F32097EE8DBAC55B035CBA2A9D608ED78A6173D610408C773C88BC6DD7E21951 - Submitted as: 0482ff32c8832ce67e0656c4a2521594d5759fc78fbb85475028767700b28ba0
- File type: pdf · Size: 90604 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/e4459eed-e494-4763-bf41-c366491c2cfb/kesazotaxineg.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 17 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://pelibifir.ru/strik?utm_term=zero+two%2527s+real+name, https://uploads.strikinglycdn.com/files/e4459eed-e494-4763-bf41-c366491c2cfb/kesazotaxineg.pdf, https://uploads.strikinglycdn.com/files/55ce28e7-db00-442e-894c-5dcd68c7ce07/wapasijepi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (12 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9915 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787931364&P2=404&P3=2&P4=eEJRijaFPdzdEXr4wYiH9qzBYrbiOd8c81CrCfhkvkW0PlqQNRUejOkjmYf1PYKo%2bQ0%2fY7WFVigvL7oEhJbFyQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787931444&P2=404&P3=2&P4=YjhzWJwaR3yeqFLdJnSMsMj2DFiupFdTzx7SJcXrWbaHQFzWyycjjlYWhuhDiMosDx%2bAXx35tBKr86qgtAovVw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\686983ee75ae4da6d85acdf409c58d11.png -
1e689c5aec6af7bbfeeb4469e8b802f7868d6aa1ab20be4dc6c278f28853f2e3 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
9f69928d38bd29b2450ef9bfb3277c76fbe9e726cecab77e4a3d45b3c29efc6c - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://pelibifir.ru/strik?utm_term=zero+two%2527s+real+name
- https://uploads.strikinglycdn.com/files/e4459eed-e494-4763-bf41-c366491c2cfb/kesazotaxineg.pdf
- https://uploads.strikinglycdn.com/files/55ce28e7-db00-442e-894c-5dcd68c7ce07/wapasijepi.pdf
- https://fadafiwu.weebly.com/uploads/1/3/5/3/135302778/figowukaxote.pdf
- https://zifidobu.weebly.com/uploads/1/3/4/3/134371145/2175612.pdf
- https://nogudoge.weebly.com/uploads/1/3/4/0/134017621/nifobefuraxise.pdf
- https://uploads.strikinglycdn.com/files/0a7a5fca-afd9-435e-8630-8662c4c6dc74/nazekuxis.pdf
- https://sixamipad.weebly.com/uploads/1/3/4/7/134726782/1460398.pdf
- https://uploads.strikinglycdn.com/files/7ed72a52-6366-4396-bf80-88bb30756023/funny_rude_christmas_songs_lyrics.pdf
- https://uploads.strikinglycdn.com/files/89917522-afd0-426b-bfed-246b2f75f7a6/marketing_management_15th_edition.pdf
- https://xubesizodumuruk.weebly.com/uploads/1/3/4/7/134703494/1eda98eead4c.pdf
- https://uploads.strikinglycdn.com/files/87b1ee9f-7366-4377-a825-b2e6fa3ce654/pupemetuxamavobuso.pdf
- https://uploads.strikinglycdn.com/files/2b227ba4-26ec-4a70-bd95-6031beed82f9/download_walkthrough_final_fantasy_7_bahasa_indonesia.pdf
- https://uploads.strikinglycdn.com/files/bbb44c65-5f2b-468c-9a08-974c1079cab5/jersey_mikes_philly_nutrition.pdf
- https://rediwikutine.weebly.com/uploads/1/3/4/0/134096605/934809.pdf
- https://nitomono.weebly.com/uploads/1/3/1/4/131454496/jeruwumemi-vuxamesu.pdf
- https://monivewuvafa.weebly.com/uploads/1/3/4/0/134096064/befitosus.pdf
- https://uploads.strikinglycdn.com/files/81fef255-d46b-4a58-ade9-15e192bed231/tubidy_mobile_musica_gratis_para_descargar_mp3.pdf
- https://uploads.strikinglycdn.com/files/3ebf81c8-69bd-4be1-af39-d8d055a2ebd4/vewusaboledak.pdf
- https://uploads.strikinglycdn.com/files/58a711cc-5d72-4726-b52d-7895a34b9a01/how_to_change_photo_into_painting_in_photoshop.pdf
- https://jafoxoxuxovawe.weebly.com/uploads/1/3/0/8/130813536/3749558.pdf
- https://sesoguxanijiba.weebly.com/uploads/1/3/5/3/135309487/razafopozedej.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- pelibifir.ru
- uploads.strikinglycdn.com
- fadafiwu.weebly.com
- zifidobu.weebly.com
- nogudoge.weebly.com
- sixamipad.weebly.com
- xubesizodumuruk.weebly.com
- rediwikutine.weebly.com
- nitomono.weebly.com
- monivewuvafa.weebly.com
- jafoxoxuxovawe.weebly.com
- sesoguxanijiba.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 162.159.142.9
- 172.66.2.5
- 52.168.117.168
- 52.110.12.47
- 135.232.92.34
- 4.230.171.124
- 72.153.5.138
- 172.215.188.232
- 203.26.79.13
- 74.178.240.61
- 20.184.175.18
- 20.236.44.162
- 52.123.129.14
- 92.223.78.30
- 172.175.111.170
- 13.89.179.12
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report