MALICIOUS — 0a8a49db53a5eadd8b55fe06bc354d9c74981928b2bbf78bb3f4e67e2633dea1
MALICIOUS — 0a8a49db53a5eadd8b55fe06bc354d9c74981928b2bbf78bb3f4e67e2633dea1 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 5 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0a8a49db53a5eadd8b55fe06bc354d9c74981928b2bbf78bb3f4e67e2633dea1 - SHA-1:
3d42c308540005d17854d8ea9fd320fe54f89ecf - MD5:
1792f9f551b7ab82b65ccd8a93c5a69b - ssdeep:
1536:i6+qCOtCYjEZpqtlyImyYNZiPa19S3cy6eb9GtBQeZXbX9x16/y/AR0Bv58:h8Yj+pkllA5e3rb9GtBQgbXh6EAgC - TLSH:
T14C37E1F33087DD9C2A474B1311A501AB309ADB4C7532EB698D48B7ACC8AC5BF6D14991 - Submitted as: 0a8a49db53a5eadd8b55fe06bc354d9c74981928b2bbf78bb3f4e67e2633dea1
- File type: pdf · Size: 73832 bytes
- Verdict: malicious (99/100)
Detections (5 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!1792F9F551B7
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PDF/Phish-FAB!1792F9F551B7 (rule
PDF/Phish-FAB!1792F9F551B7) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://crophysi.ru/123?utm_term=when+is+the+5th+wave+2+movie+coming+out, http://derekage.epizy.com/3189318833.pdf, https://sizeduxaginota.weebly.com/uploads/1/3/2/7/132712537/3735078.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 16 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (8 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9702 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9?P1=1787953558&P2=404&P3=2&P4=MG8AWaswebG1Myz7qlk0SzQvHAXUHrtL4kIIFbC2OQqcNMEP%2feKc%2f2jLpyu2rhAruFhAlIkBFQT6lwwzpMnoeA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787953578&P2=404&P3=2&P4=KAhxj9cifi%2bMiSm%2f6AMB1YEXgs4lLd17D8Q7Ton8aaZ2JE%2bVC4alweIJZ5dN3ub1cD5kf544R7OEAlPTxGLnlQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787350277&P2=404&P3=2&P4=hD%2fav8MnAJlk6jMSEhkBob6KlTlN3o8jEva2aVkJqhT1N4OqfjEdEhOWgu6sPgKkqkaTEMnmbbMp8qYifksG5g%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
3a0b2f0f496fe6252873d972d67094954b3b602690d9db2256920f2988185d28 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\d2470cf5cb1893993b7f0ff126006d1b.png -
84d5c8497426eb6d54fc0526690e38e95f5c11f4b82d28a16b930309793cdc71 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://crophysi.ru/123?utm_term=when+is+the+5th+wave+2+movie+coming+out
- http://derekage.epizy.com/3189318833.pdf
- https://sizeduxaginota.weebly.com/uploads/1/3/2/7/132712537/3735078.pdf
- https://s3.amazonaws.com/mamukawaxatali/new_song_2019_bestwap_dj.pdf
- https://donefuvo.weebly.com/uploads/1/3/1/1/131164418/wujedizuros.pdf
- https://static.s123-cdn-static.com/uploads/4428052/normal_5fe5d6a69cbd8.pdf
- https://cdn-cms.f-static.net/uploads/4475564/normal_5fea285a0fbca.pdf
- https://cdn-cms.f-static.net/uploads/4416493/normal_5fd6639ba0aec.pdf
- https://guxumexowe.weebly.com/uploads/1/3/3/9/133999944/641190.pdf
- https://cdn.sqhk.co/fuvebopeweb/Ujaicjc/44587547733.pdf
- https://galinigogazefu.weebly.com/uploads/1/3/2/6/132695851/9a0b2e0.pdf
- https://cdn.sqhk.co/pefevepufi/jghgjji/2229079160.pdf
- https://cdn.sqhk.co/buzomesil/jNieigD/legacy_golf_course_las_vegas_scorecard.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9?P1=1787953558&P2=404&P3=2&P4=MG8AWaswebG1Myz7qlk0SzQvHAXUHrtL4kIIFbC2OQqcNMEP%2feKc%2f2jLpyu2rhAruFhAlIkBFQT6lwwzpMnoeA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Embedded domains
- crophysi.ru
- derekage.epizy.com
- sizeduxaginota.weebly.com
- s3.amazonaws.com
- donefuvo.weebly.com
- static.s123-cdn-static.com
- cdn-cms.f-static.net
- guxumexowe.weebly.com
- cdn.sqhk.co
- galinigogazefu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.123.252.213
- 52.110.12.18
- 4.144.132.223
- 4.230.171.124
- 40.84.97.4
- 74.178.76.44
- 72.153.5.138
- 74.179.77.164
- 20.112.250.133
- 203.26.79.13
- 74.178.76.128
- 52.123.129.14
- 52.123.252.198
- 52.123.252.242
- 135.234.160.246
- 48.192.143.121
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report