MALICIOUS — 273461e4eecb7f7ebb280aab16010959ffdf3a69eb3f201de5882c32f26197c3
MALICIOUS — 273461e4eecb7f7ebb280aab16010959ffdf3a69eb3f201de5882c32f26197c3 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
273461e4eecb7f7ebb280aab16010959ffdf3a69eb3f201de5882c32f26197c3 - SHA-1:
fc4f96fcf4aa3d5cdc9ef37d089d736ccc82c0a4 - MD5:
fa4ba1f10de2794bb38abb4a1556fee6 - ssdeep:
1536:KVcCsk9RsCsewf8alNWToFPCKXPdMWFIc/53Wxh7/24r0HpiC:5m9R7sxuoFPCOhf4haqAF - TLSH:
T17A38CFF3209FDD0CB68B5F53BDEB10956099D64835329B60418CBA6CC9BC9BE7D20A01 - Submitted as: 273461e4eecb7f7ebb280aab16010959ffdf3a69eb3f201de5882c32f26197c3
- File type: pdf · Size: 80334 bytes
- Verdict: malicious (98/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): Trojan-JADR!FA4BA1F10DE2
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://historia-bfured.hu/userfiles/file/gurimiboja.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 23 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://sg-design.top/wp-content/plugins/super-forms/uploads/php/files/41c2cd6a5d6362a2edc802da93d2ac95/86352781229.pdf, http://historia-bfured.hu/userfiles/file/gurimiboja.pdf, http://ln2sc.com/userfiles/file/guxupimuki.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9715 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787847086&P2=404&P3=2&P4=lt8r%2fJCMznvTt6%2fNt82d8vUtph5fmtpRbZ91Gl3tVt%2fUAxdgRWmuRC6LUTGoSQsdYM89IClSvJlUF4TOi%2f3Stw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787847111&P2=404&P3=2&P4=M4V7Qsrz%2fjU3KSKou2rqHPiFZ95MimIFafPwF6diQKQZ3ZYxT5jD9XBdm8WrxN3Jif7vyiUXuE86egKotrHF5w%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787243783&P2=404&P3=2&P4=J8a4L24ZKqK5WHUmPWkSoTEcXGbdBp1eLAEJcQdobQqprwhM5ILgvwZXPZgB2H8YF3%2f3Lspavzx56MN419JXYA%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
6477d4215d008dfd52150d293da97e92548ca69c1dfabc6b70bd430e6dc3439c - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\4723fbaf7d6c3bec469748d97c34633a.png -
05ace11cbe3bae46932ea01343dc1b6afa48f694c5822bf4d19b936752bfca22 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/Gsjc/~3/6Zflnl449io/uplcv?utm_term=fly+me+to+the+moon+acoustic+guitar+chords
- https://sg-design.top/wp-content/plugins/super-forms/uploads/php/files/41c2cd6a5d6362a2edc802da93d2ac95/86352781229.pdf
- http://historia-bfured.hu/userfiles/file/gurimiboja.pdf
- http://ln2sc.com/userfiles/file/guxupimuki.pdf
- http://about-dogs.ru/upload/file/vosuvirifowazosu.pdf
- http://movitecnic.com/ressource/site-image/files/10346105641.pdf
- http://auto-spec.ca/fck/file/gabololodutijagabokepiko.pdf
- https://happy-playground.gr/uploads/_uploads/files/32625548041.pdf
- http://arci-mp.fr/admin/File/pezazupedafibo.pdf
- http://banghetretruc.com/media/ftp/file/kemimotaxitizepaxotanavo.pdf
- https://mamproducciones.es/wp-content/plugins/formcraft/file-upload/server/content/files/16152860ca9103---92604453916.pdf
- http://ventilatoryzlin.cz/images/file/3505823491.pdf
- https://dakhoathienhoa.net/images/files/67270474617.pdf
- http://szguilong.com/userfiles/files/68394516162.pdf
- http://awfiowv.love-mrt.com/upload/files/mejemapikanovabiximidusod.pdf
- http://kirakuramen.com/uploads/files/nemavixabe.pdf
- https://oconecorisc.ro/admin/UserFiles/file/87146785403.pdf
- https://braveathlete.net/geektic/files/fepisoxesupevokizazez.pdf
- https://felicityokolo.com/file/99395534855.pdf
- https://flcevent.fcu.edu.tw/plugin/ce1/ckfinder/userfiles/files/20211010164651.pdf
- https://regenerativetherapyforpain.com/wp-content/plugins/super-forms/uploads/php/files/cd5063cab1871f3dc960caf217b33be9/lufazolotoleladutuwop.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- feedproxy.google.com
- sg-design.top
- ln2sc.com
- about-dogs.ru
- movitecnic.com
- auto-spec.ca
- arci-mp.fr
- banghetretruc.com
- mamproducciones.es
- dakhoathienhoa.net
- szguilong.com
- awfiowv.love-mrt.com
- kirakuramen.com
- braveathlete.net
- felicityokolo.com
- flcevent.fcu.edu.tw
- regenerativetherapyforpain.com
- www.w3.org
- purl.org
- ns.adobe.com
- historia-bfured.hu
- happy-playground.gr
- ventilatoryzlin.cz
- oconecorisc.ro
Embedded IP addresses
- 4.150.223.98
- 52.123.252.247
- 52.110.12.47
- 52.110.12.26
- 4.230.171.124
- 4.247.188.224
- 52.230.60.54
- 74.178.240.51
- 20.231.239.246
- 135.232.92.137
- 74.179.77.204
- 52.123.128.14
- 40.99.133.210
- 135.234.160.246
- 104.208.16.94
- 52.123.252.229
- 72.145.35.98
- 203.26.79.13
- 52.123.252.234
- 92.223.78.30
- 51.105.71.137
- 51.104.15.253
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report