MALICIOUS — 28d76573dd0433bd45ad4e889d1840d3f022a18f2441936e7675756b29047ad1
MALICIOUS — 28d76573dd0433bd45ad4e889d1840d3f022a18f2441936e7675756b29047ad1 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
28d76573dd0433bd45ad4e889d1840d3f022a18f2441936e7675756b29047ad1 - SHA-1:
875d20dce6d0197883749b01890ebbc5b51c3b39 - MD5:
343724f69799d1877c6b1c16e867fc42 - ssdeep:
1536:kNCxGXl+n6IlkF9nWAWjUad7hz6BjFZ2ijWW4UzV8jB3a7gW8pO7l:pGXwBlIUlH716bZ2i94aE3a7L7l - TLSH:
T14A36CFF7515BCD4CB74F9B026AB712A6F48EC78821A1E690818CAB54D2ACC7F6D41E40 - Submitted as: 28d76573dd0433bd45ad4e889d1840d3f022a18f2441936e7675756b29047ad1
- File type: pdf · Size: 68082 bytes
- Verdict: malicious (98/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://trenermichal.pl/wp-content/plugins/formcraft/file-upload/server/content/files/1614e4df6456f8---27111198005.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 18 external host(s) and 8 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://queensparkview.com/image/upload/File/lisibufisa.pdf, http://constantemail.com/userfiles/file/163105278053403616946.pdf, http://am-assets.com/aom/magnolia/userfiles/file/mesukibamigazilomar.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
5674 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
9cb52477319b08a37676e9ec3402a99f5a5efeb80598d1bf5d022ce691518e95 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/A3Ryygt5BCM/uplcv?utm_term=rom+redmi+note+5
- http://queensparkview.com/image/upload/File/lisibufisa.pdf
- http://constantemail.com/userfiles/file/163105278053403616946.pdf
- http://am-assets.com/aom/magnolia/userfiles/file/mesukibamigazilomar.pdf
- http://vmkmsz.hu/userfiles/file/94458666003.pdf
- http://trenermichal.pl/wp-content/plugins/formcraft/file-upload/server/content/files/1614e4df6456f8---27111198005.pdf
- http://v-lukomorie.com/uploader/files/wilosuxelapixajifusu.pdf
- http://zamel2.pl/userfiles/file/lonivitowumuti.pdf
- https://cabinetscounters.com/ckfinder/userfiles/files/sutori.pdf
- http://pneusmarene.it/images/file/1355114983.pdf
- https://efckrakow.pl/userfiles/file/navugivin.pdf
- http://midel.me/userfiles/file/1352390107.pdf
- http://hengtongrongshang.com/jingkelun/userfiles/files/20210912011503.pdf
- https://dailyiat.com/html_upload/file/mukoxotitolu.pdf
- https://clubkdo.fr/img/pics/files/7548451023.pdf
- http://shangrilatheshow.com/ckfinder/userfiles/files/22373658173.pdf
- http://mocphatreal.com/assets/images/ckfinder/files/66026048254.pdf
- http://casaperugia.fr/userfiles/file/xadagog.pdf
- http://rulife.ru/ckfinder/userfiles/files/tatorosexalefun.pdf
- https://coherence.cz/userfiles/file/wifexiriputisal.pdf
- http://balmybnb.com/t/tutorfirm/uploads/ck/files/letunofowumojijusekometiw.pdf
- http://fukaofoods.tw/uploads/files/202109202349305662.pdf
- http://sdes.in/uploads/gemis.pdf
- https://doxity.ro/ckfinder/userfiles/files/51099503693.pdf
- https://svltv.in/userfiles/files/3274908259.pdf
Embedded domains
- feedproxy.google.com
- queensparkview.com
- constantemail.com
- am-assets.com
- trenermichal.pl
- v-lukomorie.com
- zamel2.pl
- cabinetscounters.com
- pneusmarene.it
- efckrakow.pl
- midel.me
- hengtongrongshang.com
- dailyiat.com
- clubkdo.fr
- shangrilatheshow.com
- mocphatreal.com
- casaperugia.fr
- rulife.ru
- balmybnb.com
- fukaofoods.tw
- sdes.in
- svltv.in
- vmkmsz.hu
- coherence.cz
- doxity.ro
Embedded IP addresses
- 20.42.73.28
- 52.110.12.47
- 52.110.12.45
- 4.230.171.124
- 72.153.5.128
- 203.26.79.13
- 52.230.59.222
- 4.150.223.102
- 20.231.239.246
- 40.99.133.242
- 74.178.240.61
- 52.123.129.14
- 52.182.143.212
- 20.42.179.192
- 20.184.175.5
- 4.209.250.170
- 20.42.65.93
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report