MALICIOUS — 1ef527d33f346fda93515d33a4fecd42c50b8bd94ea2e311bd8a33d059d9e3c5
MALICIOUS — 1ef527d33f346fda93515d33a4fecd42c50b8bd94ea2e311bd8a33d059d9e3c5 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
1ef527d33f346fda93515d33a4fecd42c50b8bd94ea2e311bd8a33d059d9e3c5 - SHA-1:
80d0dedf1475ced5b1114836eec8ad8346f4a765 - MD5:
9da17b7d20aea52371c129da8e01a12e - ssdeep:
1536:UmY7QXdxCuea80x+7XVO15Fw6wB5EmF2xaWlkyEonWspO2Ukq:RYSxCueaRcw15FEB+A2xgyEoa2e - TLSH:
T1DA37BFE32097DD8C664BCB437EEA1169648ED7456663DF6004C8BA7C807C9BDBF00A61 - Submitted as: 1ef527d33f346fda93515d33a4fecd42c50b8bd94ea2e311bd8a33d059d9e3c5
- File type: pdf · Size: 73034 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://royalgoodviewresort.com/Uploads/file/fezotuvavefim.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 21 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://catamma.ru/uplcv?utm_term=a+quiet+place+2+free+full+movie+online, http://brickchamber.com/ckfinder/userfiles/files/minubu.pdf, https://www.shropshirefurniture.co.uk/admin/ckfinder/userfiles/files/13522361082.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9561 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787842839&P2=404&P3=2&P4=RBdHV1vBZp37QF1RIsYWnxeSGjcVl469riFHTXy6QFam2g2a2V9unQ4oOvGvDILVrC07xn0Gk6ZtdoozxJ7nGg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
04a96dc0f935e80224dc85cf4fa6d50cb0588e970bb44a1046a8d71603a28406 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\7f7119b7a06e570dabea3b2e6040ad39.png -
dade2808960167b4d0fc17529b224e7403f2e772e6402930e0bb9bbea0f30f94 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://catamma.ru/uplcv?utm_term=a+quiet+place+2+free+full+movie+online
- http://brickchamber.com/ckfinder/userfiles/files/minubu.pdf
- https://www.shropshirefurniture.co.uk/admin/ckfinder/userfiles/files/13522361082.pdf
- http://files.ibiza-ferien.de/file/ludusurapin.pdf
- https://www.kiakaha.gr/wp-content/plugins/super-forms/uploads/php/files/uqovfqdmsg2ejvu3jh3cco8a49/lasikemavexodiko.pdf
- http://js-space.de/userfiles/file/4610629850.pdf
- https://carcarnet.com/home/sandbox/domains/hkdance.tritek.hk/public_html/ckfinder/userfiles/files/93006853574.pdf
- http://royalgoodviewresort.com/Uploads/file/fezotuvavefim.pdf
- http://digjamaica.com/app/webroot/files/feveramemewu.pdf
- http://puntolinea.org/userfiles/files/21057691665.pdf
- https://www.swx.global/wp-content/plugins/super-forms/uploads/php/files/e294fa2a6f20df30a7c68f9a2da2c869/3569034192.pdf
- http://decom.pro/admin/ckfinder/userfiles/files/44629015812.pdf
- http://rapabzenec.cz/obrazky/files/32407091413.pdf
- http://runo34.ru/attachments/file/tuxatulajodowaxa.pdf
- https://www.elektrobetrieb-scholz.de/wp-content/plugins/formcraft/file-upload/server/content/files/1613411361d59e---61455354999.pdf
- https://alwillislifecenter.org/ckfinder/userfiles/files/lobax.pdf
- http://caribsplash.org/wp-content/plugins/formcraft/file-upload/server/content/files/1614e6919aef57---61299876335.pdf
- https://brihat-group.com/assets/userfiles/files/limamabigesiverawaz.pdf
- http://nkmate.com/FileData/ckfinder/files/20210906_CB1D7AD68B796E31.pdf
- http://2girlstrippin.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614076104ec5f---98852436838.pdf
- https://festivalecolo.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16130f6fe2b01e---muxumedewilepixozu.pdf
- http://cukorbetegshop.hu/files/86360592675.pdf
- https://www.educazionesessuale-scuola.ch/ck/ckfinder/userfiles/files/teberikit.pdf
- https://www.pharmaright.ca/wp-content/plugins/super-forms/uploads/php/files/d0fh8tjgmckfn3hvkkt5ft4jf0/zubazemo.pdf
- http://aaronandanthony.com/userfiles/files/95338591633.pdf
Embedded domains
- catamma.ru
- brickchamber.com
- www.shropshirefurniture.co.uk
- files.ibiza-ferien.de
- js-space.de
- carcarnet.com
- hkdance.tritek.hk
- royalgoodviewresort.com
- digjamaica.com
- puntolinea.org
- decom.pro
- runo34.ru
- www.elektrobetrieb-scholz.de
- alwillislifecenter.org
- caribsplash.org
- brihat-group.com
- nkmate.com
- 2girlstrippin.com
- festivalecolo.ca
- www.educazionesessuale-scuola.ch
- www.pharmaright.ca
- aaronandanthony.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 172.233.212.90
- 57.154.63.210
- 4.207.44.72
- 4.150.223.108
- 135.233.95.80
- 52.110.12.11
- 48.211.4.16
- 4.230.171.124
- 72.154.7.100
- 203.26.79.13
- 74.179.77.204
- 135.233.95.135
- 20.112.250.133
- 52.123.128.14
- 92.223.78.30
- 135.234.160.246
- 74.178.232.29
- 20.42.65.94
- 48.199.12.1
- 52.168.112.66
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report