MALICIOUS — 13eacb0e1dff169846e989da38054d5913aaecf6613978fa8514e193ec42431a
MALICIOUS — 13eacb0e1dff169846e989da38054d5913aaecf6613978fa8514e193ec42431a is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
13eacb0e1dff169846e989da38054d5913aaecf6613978fa8514e193ec42431a - SHA-1:
ad8c82fdd6c89b975c8152bedfae9e997a8ba277 - MD5:
77fc509ce5b5fa3b32445105ab284d85 - ssdeep:
1536:Ia2ZhnmHUFRbvbFtOiEy1b6WmYh9tiMG7yHfcWQpOCmaWeL3:ahm07bvbrjDbUYhbiVMfbCm9q - TLSH:
T15938CFF311EBCD4D764BDF0379EB2278A0CAE78C2162D6504484776CC9AC5BEAE11A11 - Submitted as: 13eacb0e1dff169846e989da38054d5913aaecf6613978fa8514e193ec42431a
- File type: pdf · Size: 76768 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://bscsaoner.in/ckfinder/userfiles/files/32268835704.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 20 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://philabc.ru/uplcv?utm_term=the+most+dangerous+game+short+story+characters, https://californiaoptionsrealestate.com/wp-content/plugins/super-forms/uploads/php/files/47a377c5630d38a7d4a800aa3ffa91d8/gitifup.pdf, http://knuhpharm.kr/userfiles/file/20210912035554.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9561 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787794545&P2=404&P3=2&P4=b5MM2TtAQ9EVPtiYFLlrajkuxXcdELyLN5pd5FNfgStOXz3PnUH38na9iVH6QRDF2DJHNttMgFC9%2f754GBcjKA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
c71ed2b1b5de1b427e3ff1b264cb8d297549509fd0c9bbf083f73b62be9539c8 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\3eb7762786bb176013686f1f870dbfdf.png -
aa201276b4f63574a314b02d2c891d3d5edf4afea309bf26eb9eb8bbb5d1c1e5 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://philabc.ru/uplcv?utm_term=the+most+dangerous+game+short+story+characters
- https://californiaoptionsrealestate.com/wp-content/plugins/super-forms/uploads/php/files/47a377c5630d38a7d4a800aa3ffa91d8/gitifup.pdf
- http://knuhpharm.kr/userfiles/file/20210912035554.pdf
- https://umutisi.com/umut/upload/files/dutubuwizamukusumasebazar.pdf
- https://nhaccugiare24h.com/uploads/userfiles/file/jifafila.pdf
- https://hchoanglong.vn/userfiles/file/fodesisebuvawinej.pdf
- https://franciscovalles.comtraining.cl/userfiles/files/tibulade.pdf
- http://bscsaoner.in/ckfinder/userfiles/files/32268835704.pdf
- http://msci.com.ng/wp-content/plugins/formcraft/file-upload/server/content/files/1612ecf83260e3---favotiraxuvabiju.pdf
- http://maginsaatmetal.com/resimlerfiles/43527530275.pdf
- http://gadkowski.pl/repository/filemanager/file/61747741998.pdf
- http://abcbyspu.com/ckfinder/images_store/files/toxim.pdf
- https://hongdung.vn/ckeditor/images/files/68506435679.pdf
- http://nuovartea.eu/userfiles/files/murebusu.pdf
- http://archiw.bibliotekalesmierz.eu/img/upload/files/veresimoxowiremumudir.pdf
- https://arrayamed.com/userfiles/file/47798147513.pdf
- https://edenestates.com/ckfinder/userfiles/files/ruwapiwumukipilo.pdf
- https://faktxeber.ru/resimler/files/redaxipelijitojubefo.pdf
- https://ystechpro.com/nbloom/fckuploads/file/wonodojuvaduwowifisukur.pdf
- http://traktor-tv.de/sites/default/files/file/51792479831.pdf
- https://labelmarket.eu/data/file/79605302292.pdf
- https://romalasergroup.com/userfiles/files/pifemesabukopomunakeru.pdf
- http://gwtcs.org/Content/uploads/files/46584805141.pdf
- http://canxetaianhduc.com/images/file/rofurukekowapekeruku.pdf
- https://bodzlomu.com/userfiles/file/62691829176.pdf
Embedded domains
- philabc.ru
- californiaoptionsrealestate.com
- knuhpharm.kr
- umutisi.com
- nhaccugiare24h.com
- bscsaoner.in
- maginsaatmetal.com
- gadkowski.pl
- abcbyspu.com
- nuovartea.eu
- archiw.bibliotekalesmierz.eu
- arrayamed.com
- edenestates.com
- faktxeber.ru
- ystechpro.com
- traktor-tv.de
- labelmarket.eu
- romalasergroup.com
- gwtcs.org
- canxetaianhduc.com
- bodzlomu.com
- www.w3.org
- purl.org
- ns.adobe.com
- hchoanglong.vn
Embedded IP addresses
- 4.150.223.104
- 52.168.117.174
- 52.123.252.197
- 52.123.252.222
- 20.165.94.46
- 52.110.12.31
- 4.230.171.124
- 203.26.79.13
- 4.247.188.233
- 74.178.76.128
- 135.232.92.97
- 52.123.252.195
- 20.236.44.162
- 40.99.134.18
- 52.123.129.14
- 135.234.160.245
- 48.200.63.27
- 4.150.223.106
- 20.42.72.131
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report