MALICIOUS — 13897745309.pdf
MALICIOUS — 13897745309.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
1c7f15e7a91b0a06906a0de8b3c20dc4b109f275a63df37f545be239021962a7 - SHA-1:
13f62b1af78081fe9ee684d8c68f1fba467f757d - MD5:
21cceb9e8e930811fa5ce8eda2dea684 - ssdeep:
1536:NTjOJZmcoJeLrm96JmpdHE2Dh6pP3vvWLtpyhLDu3VEcWoWcpOmb1i:JOjm6r26JmY2F6pPotpyxD4VEcWzmM - TLSH:
T11037BFB332E7DD4CB6869B077DFA1169708AD2841521EFA0418CB7AC98BC67DBF20511 - Submitted as: 13897745309.pdf
- File type: pdf · Size: 76038 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 14 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: http://khangvietdn.com/uploads/file/fuver.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://mayinmaunhat.com/upload/files/63858124995.pdf, https://sitarasign.ir/data/file/simasosuxekexojopoz.pdf, https://denizlihorozu.com/resimler/files/4718152269.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9696 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787776140&P2=404&P3=2&P4=F77vusnTkQRs8x3KsJv10oO%2bYk33aJ2FHz%2fKI4exAmtsLujtbnV0IaC6aUqMMreA1FadmeWgfHaNiUDf0L6UDQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787776193&P2=404&P3=2&P4=V%2fRh9%2fi6MCErSfHHFsFrUG0HA9mz0ee2FY0JOa0eQSFjPkyhiRzL7c%2fxl9lq4TfZhG1lp7O1N%2f7NOp%2b%2bqA0n8A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/b56480f9-8215-4de7-ba7e-8e690088d21d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
6f0007f59d4cc7414c7d0415c2eab2fc2d94302d71e2b0a4a1fe317c0dc62555 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\39db32714a28fddce8306a1878599fd7.png -
62e8ac5edd53aef8a7001c88e497cd4c097cb7429a15cbbf0165112db7eeba08 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1xuhb7AK25c/uplcv?utm_term=essentials+of+public+health+dentistry+soben+peter+6th+edition+pdf+download
- http://mayinmaunhat.com/upload/files/63858124995.pdf
- https://sitarasign.ir/data/file/simasosuxekexojopoz.pdf
- https://denizlihorozu.com/resimler/files/4718152269.pdf
- https://loan-financial.com/wp-content/plugins/super-forms/uploads/php/files/8069b0417deed16a023d2a505120e245/webobubewo.pdf
- https://hotelritariccione.it/wp-content/plugins/formcraft/file-upload/server/content/files/1613601ff42088---xuvafezonejatij.pdf
- http://ztkammer.at/uploads/file/90711021776.pdf
- http://www.boldino-hotel.com/ckfinder/userfiles/files/xopowobafonoxusawofuwav.pdf
- https://wedding-photos.cz/userfiles/file/71147490502.pdf
- http://ok-poland.com/userfiles/file/9307891342.pdf
- http://khangvietdn.com/uploads/file/fuver.pdf
- https://maloneslandscape.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613681b88cf29---niregagezemepazur.pdf
- http://biosurfest.com/userfiles/files/gelapuzolefod.pdf
- https://bepcongnghiepphuchung.vn/userfiles/file/zujusaseketikinabunefeba.pdf
- http://brighterhealthcare.co.uk/wp-content/plugins/super-forms/uploads/php/files/v9fkgjb3271knkp06h6v64n9mr/90709118960.pdf
- https://ocvirapuato.com.mx/wp-content/plugins/super-forms/uploads/php/files/f1face1854babf07590077621dd68415/48997184786.pdf
- http://shuimotongyuan.com/userfiles/file/bapuxi.pdf
- http://creativeindustries.ru/uploads/userfiles/file/65334122070.pdf
- http://pro-group.ru/userfiles/files/sawamovusa.pdf
- http://zhizhencn.com/filespath/files/20210920051855.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/1615323a7b0f46---33875876098.pdf
- https://alamansyria.com/userfiles/file/tokizivizawuko.pdf
- https://festivaldelmaridaje.com/sgi_userfiles/userfiles/files/14031841957.pdf
- http://diamantina-joaillerie.com/ckfinder/userfiles/files/kusapu.pdf
- http://printific.com/images/contentimages/files/83293411820.pdf
Embedded domains
- feedproxy.google.com
- mayinmaunhat.com
- sitarasign.ir
- denizlihorozu.com
- loan-financial.com
- hotelritariccione.it
- www.boldino-hotel.com
- ok-poland.com
- khangvietdn.com
- maloneslandscape.com
- biosurfest.com
- brighterhealthcare.co.uk
- ocvirapuato.com.mx
- shuimotongyuan.com
- creativeindustries.ru
- pro-group.ru
- zhizhencn.com
- www.1000ena.com
- alamansyria.com
- festivaldelmaridaje.com
- diamantina-joaillerie.com
- printific.com
- krusomying.com
- www.w3.org
- purl.org
Embedded IP addresses
- 52.123.252.240
- 172.215.188.225
- 4.230.171.124
- 52.253.84.76
- 51.116.246.105
- 20.165.94.54
- 20.76.201.171
- 52.123.128.14
- 40.99.134.18
- 135.233.95.80
- 203.26.79.13
- 20.165.94.63
- 48.192.143.121
- 52.168.117.175
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report