MALICIOUS — 102588cf5b3263254d1b8c2965ab42741de4e3225d4a97c4da585a376202ac63
MALICIOUS — 102588cf5b3263254d1b8c2965ab42741de4e3225d4a97c4da585a376202ac63 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
102588cf5b3263254d1b8c2965ab42741de4e3225d4a97c4da585a376202ac63 - SHA-1:
38b9d92ca635bed5d5572ee31e37d184fb0a63aa - MD5:
284355661e2c69361a57069c4a004972 - ssdeep:
1536:pJKdWHAxgT4R7XnEdjp0eboMumxdqynDH+H6WaabsJV5TWspO2wL3:idWgxgK7UVp0SfuFKeHDbsX5O28 - TLSH:
T15D38CFE32097DD9C73579B437EEA11A9644AE3481221EB5040C8B76CA97C4FE7F40A72 - Submitted as: 102588cf5b3263254d1b8c2965ab42741de4e3225d4a97c4da585a376202ac63
- File type: pdf · Size: 77242 bytes
- Verdict: malicious (72/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 72/100 is the fusion of 6 weighted signals:
- Contacted 16 external host(s) at runtime (6 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: http://novichiha.ru/pic/file/24539788348.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://szermgrt.hu/uploads/ckfinder/userfiles/files/tabifaxadoxokutafed.pdf, http://yokohama-model.com/userfiles/files/98788565084.pdf, http://unitec-egypt.net/userfiles/file/sijokulilufenunesixorow.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9698 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- c.pki.goog
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787870492&P2=404&P3=2&P4=eOBi65hf8mK3uuROecf3amAbbAC7Ba9f9PZID2Z9Dwv%2fGrvwqY4WsxF%2b6QYD3bFZn10ezPzOWgG3Ei%2fTKCs0kA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787870527&P2=404&P3=2&P4=d4CvrySBshNcrG65pTc06sV5DRpKI83u2S%2fNcIwkXsuBC7Xb59HSTMdHY35x%2buA3s9eSAT47mF9sL3WYe6Qznw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\cdb70d843773026d51698334ffe3a610.png -
9f5e4c0bdbfabafb3f41f58ff7cc32c515c37c352efa16b302092b7e840e17d4 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
cd97a3dcc46c3a695d26ae6c4df913de784653509ac80e56b36d51e8931c22d2 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- http://feedproxy.google.com/~r/MbOu/~3/1hHberoKktI/uplcv?utm_term=forming+and+naming+ionic+compounds+lab
- http://szermgrt.hu/uploads/ckfinder/userfiles/files/tabifaxadoxokutafed.pdf
- http://yokohama-model.com/userfiles/files/98788565084.pdf
- http://unitec-egypt.net/userfiles/file/sijokulilufenunesixorow.pdf
- http://www.petersonassoc.com/emailimages/file/lepatopofatud.pdf
- http://novichiha.ru/pic/file/24539788348.pdf
- https://portalbime.com/UploadedFiles/New/file/5702988862.pdf
- https://thaiwoodengames.com/files/upload/files/30888493553.pdf
- http://gearcon-eng.com/file_media/file_image/file/82048114415.pdf
- http://shbaicun.com/userfiles/file/2021090807441873499.pdf
- http://tugrabilgisayar.net/resimler/files/49351479615.pdf
- http://www.naraihillgolf.com/admin/userfiles/file/87048837169.pdf
- http://3xlove.com/uploadfile/file/nunetapogepujoji.pdf
- http://hidropro.hu/upload/fezobidazebusika.pdf
- http://massimosusto.eu/userfiles/files/42229742025.pdf
- https://414movement.com/wp-content/plugins/super-forms/uploads/php/files/648adb22d803d6516869c6c23968c286/xoluzedupososisajugexawi.pdf
- https://zerling.eu/nico/images/files/20965126841.pdf
- https://erdenetpost.mn/userfiles/files/19739323933.pdf
- https://eliteprotectiveservices.net/ckfinder/userfiles/files/65399192389.pdf
- http://2222.netsociality.com/upload/files/gozewowapolebabuf.pdf
- https://estidevelopers.com/wp-content/plugins/super-forms/uploads/php/files/ef3596051a3c18b19f8390466b961d85/31878797115.pdf
- https://aletihad-group.com/userfiles/files/22438735844.pdf
- https://bibonatura.hu/ckfinder/userfiles/files/69800793307.pdf
- http://gesundimjob.at/images/content/files/37593815181.pdf
- http://czechnews.cz/userfiles/files/35213026618.pdf
Embedded domains
- feedproxy.google.com
- yokohama-model.com
- unitec-egypt.net
- www.petersonassoc.com
- novichiha.ru
- portalbime.com
- thaiwoodengames.com
- gearcon-eng.com
- shbaicun.com
- tugrabilgisayar.net
- www.naraihillgolf.com
- 3xlove.com
- massimosusto.eu
- 414movement.com
- zerling.eu
- eliteprotectiveservices.net
- 2222.netsociality.com
- estidevelopers.com
- aletihad-group.com
- www.w3.org
- purl.org
- ns.adobe.com
- szermgrt.hu
- hidropro.hu
- erdenetpost.mn
Embedded IP addresses
- 20.50.201.205
- 52.110.12.3
- 48.211.4.16
- 4.230.171.124
- 20.247.184.197
- 20.165.94.63
- 52.168.117.171
- 20.231.239.246
- 52.123.128.14
- 40.99.133.226
- 135.234.160.245
- 72.153.5.139
- 203.26.79.13
- 52.123.252.246
- 52.123.252.219
- 4.150.223.113
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report