MALICIOUS — 216ee2e95a6ed07db1120aba2d0e40f7c8f6d667f2f4602e9ffade7cd56a1c53
MALICIOUS — 216ee2e95a6ed07db1120aba2d0e40f7c8f6d667f2f4602e9ffade7cd56a1c53 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
216ee2e95a6ed07db1120aba2d0e40f7c8f6d667f2f4602e9ffade7cd56a1c53 - SHA-1:
842e26e63c55df589a6522372ba624be38944456 - MD5:
c1ad990bd3ef39278ce82afcc743e1f7 - ssdeep:
1536:VVFqW0wsrZo/+hBG/QQ6mtrkZGq7z0hdvWGpOKCWNcDSUa3+RdCKrNXAvQ:zFqW0Pm/GB4K0swhdQKvcD83+RdVrNT - TLSH:
T17637B0F311EBDD4C378E9B439DE70299A187C7885172EBA04184B66C917CABE7F10690 - Submitted as: 216ee2e95a6ed07db1120aba2d0e40f7c8f6d667f2f4602e9ffade7cd56a1c53
- File type: pdf · Size: 72050 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://ambvetesopo.eu/userfiles/files/39643439525.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 17 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://ambvetesopo.eu/userfiles/files/39643439525.pdf, http://teacherandtraining.com/coj_u/KK/userfiles/files/14819637784.pdf, https://citytrafik.nu/images/file/jikaxabate.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9733 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
14228f3cd1aa4822c5b4bf80dfc67c5095757c8136dd9dcc8d3554a888be9562 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\c1d070bed0fe50d46000e7f2c6ad8e89.png -
96cb4a2ebac5370d397251ea906e118f94553536c792576984c2ed5a722b7949 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/fzgW7-mxBc0/uplcv?utm_term=coins+from+gyms+pokemon+go
- http://ambvetesopo.eu/userfiles/files/39643439525.pdf
- http://teacherandtraining.com/coj_u/KK/userfiles/files/14819637784.pdf
- https://citytrafik.nu/images/file/jikaxabate.pdf
- http://ovecollection.com/royal/admin/images/products/file/kugiwepimudirodisopuvijo.pdf
- http://jayeonrak.com/upfile_editor/2021/files/92655421751.pdf
- http://aven.su/userfiles/file/2924199099.pdf
- https://razdolle.by/wp-content/plugins/super-forms/uploads/php/files/e7qn8kgsv210ec32vcqr2pqp53/63176891322.pdf
- http://sarigol.kr/userData/ebizro_board/file/11082335144.pdf
- http://ladispensadicampagna.it/uploads/assets/file/69157157462.pdf
- http://shijijiaming.net/filespath/files/20210911160504.pdf
- http://sarahscupcakery.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612fe122002c3---nugojimagunubunik.pdf
- https://markmont.eu/editor_uploads/system/files/67366846935.pdf
- http://www.itbaloch.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612ea16a52e77---9104618802.pdf
- http://www.predoisiasociatii.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1613749e16b7da---85601112127.pdf
- http://topspeed4wd.com/ckfinder/userfiles/files/migerofemigigabav.pdf
- http://stadtbild-intervention.de/Quansis/ckfinder/userfiles/files/44548468352.pdf
- https://batdongsandothanh.vn/luutru/files/punujekegoxozagan.pdf
- http://www.acefence.com/wp-content/plugins/formcraft/file-upload/server/content/files/16137b78214fed---22976340790.pdf
- http://fuzoku-kyujin.jp/ckfinder/userfiles/files/35607690803.pdf
- https://astoriareiki.com/wp-content/plugins/super-forms/uploads/php/files/43cc9495f4b4f760a45558c6c77aee71/jikiwovivozoxolujo.pdf
- https://www.histoiresdegroupes.com/wp-content/plugins/formcraft/file-upload/server/content/files/161395da2e49aa---bipexuzegej.pdf
- http://energcomb.net/cms_enercomb/sgi_userfiles/userfiles/files/3372589119.pdf
- http://advocaatindex.nl/images/uploads/kumabewanusagisobipino.pdf
- http://munsusa.org/userfiles/file/20210912054936.pdf
Embedded domains
- feedproxy.google.com
- ambvetesopo.eu
- teacherandtraining.com
- ovecollection.com
- jayeonrak.com
- aven.su
- sarigol.kr
- ladispensadicampagna.it
- shijijiaming.net
- sarahscupcakery.com
- markmont.eu
- www.itbaloch.com
- topspeed4wd.com
- stadtbild-intervention.de
- www.acefence.com
- fuzoku-kyujin.jp
- astoriareiki.com
- www.histoiresdegroupes.com
- energcomb.net
- advocaatindex.nl
- munsusa.org
- kraljicabih.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 172.66.2.5
- 40.74.98.196
- 4.144.132.223
- 4.230.171.124
- 57.154.63.210
- 72.153.5.129
- 203.26.79.13
- 74.178.240.51
- 20.112.250.133
- 74.178.76.128
- 20.165.94.63
- 52.123.128.14
- 40.104.4.2
- 40.79.141.152
- 52.123.252.244
- 13.69.116.105
- 20.184.175.19
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report