MALICIOUS — 2efb942d6d211ff4eeae48897d39eae6c6c4c5c947e9ea2e729323dd0389c494
MALICIOUS — 2efb942d6d211ff4eeae48897d39eae6c6c4c5c947e9ea2e729323dd0389c494 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
2efb942d6d211ff4eeae48897d39eae6c6c4c5c947e9ea2e729323dd0389c494 - SHA-1:
a1bedc3b3060f09476d2c870b96face835f599cc - MD5:
bbfe41790fd2890008662beb94b627ac - ssdeep:
1536:r6rlsFzN25yxLbk9EnZLo3WndLzkd8qWkNpOPaW22iS7CHX8Demc7Ms7r0:mSzNeyxKEZL7nlzkdUPGSg8DJAs - TLSH:
T14838C0F32097DD8C774B4F0326B711B9508BD7892076DAA4408CBB6CD4BC9BEAE04961 - Submitted as: 2efb942d6d211ff4eeae48897d39eae6c6c4c5c947e9ea2e729323dd0389c494
- File type: pdf · Size: 82520 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://barudan.hk/UploadFile/file/20210606071405779.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 15 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://primewestelectrical.com/wp-content/plugins/super-forms/uploads/php/files/290d347f60bee415fbb9bb666537f78a/nejoremetibujozo.pdf, http://www.phonefixcomo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606c7fb708ca7---68428991738.pdf, http://sanitaerprofi.ch/fckeditor/editor/images/file/88025323647.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9824 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\acb08891edd9a38826727ec948608db9.png -
2302342857ee0bd8d39de016dbb4bf5f72126fbc15774e10f3aedcce658345e1 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
b772de4e4dee990a0faec288e637b44d724d5b419d77efc1ebab80e03cab21c2 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/fzgW7-mxBc0/uplcv?utm_term=chocolate+delight+recipe+with+graham+cracker+crust
- https://primewestelectrical.com/wp-content/plugins/super-forms/uploads/php/files/290d347f60bee415fbb9bb666537f78a/nejoremetibujozo.pdf
- http://www.phonefixcomo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606c7fb708ca7---68428991738.pdf
- http://sanitaerprofi.ch/fckeditor/editor/images/file/88025323647.pdf
- http://www.victorian-manor.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/160777aaf0c767---kutuvojifanikanu.pdf
- https://www.vibrationmonitoring.asia/wp-content/plugins/formcraft/file-upload/server/content/files/16098a88b093f4---bifegawifufiboz.pdf
- http://barudan.hk/UploadFile/file/20210606071405779.pdf
- http://caribsplash.org/wp-content/plugins/formcraft/file-upload/server/content/files/160bce035c7441---tufovujikusilez.pdf
- https://acethamessecurity.co.uk/wp-content/plugins/super-forms/uploads/php/files/3f07835a0479cfbe81ea80b952e50ad7/movozemu.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d64226a747c---92733625709.pdf
- https://adbadog.com/wp-content/plugins/super-forms/uploads/php/files/6d3d97b7839adeae81541e39f235ea05/29599083582.pdf
- http://compie.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160c7a7bf5c8af---mobonizavivibirifewoxes.pdf
- http://lifestyleufa.ru/wp-content/plugins/super-forms/uploads/php/files/e4e8145e0358395f8386c353bc4aa509/30451986684.pdf
- https://mediabandit.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b7577befdcc---73557681096.pdf
- http://www.sunarsurdurulebilir.com/wp-content/plugins/super-forms/uploads/php/files/ic9uvniqc6tc1pv0bhrsi94790/80262913097.pdf
- http://svenstavik.com/wp-content/plugins/formcraft/file-upload/server/content/files/16096e1b48594f---vowanufizizibam.pdf
- https://zegabilisim.com/calisma2/files/uploads/71602651053.pdf
- https://aftaplan.com/works/peepsparty/html/upload_files/file/69679406387.pdf
- http://www.olympussverige.se/wp-content/plugins/super-forms/uploads/php/files/7ts1l4gi1jib8p02j6eu7el1gi/22697666541.pdf
- http://stillwaterponies83.com/clients/74660/File/fodoligalisexopakite.pdf
- http://gw73patriots.com/clients/1/1e/1ed986c9d410becccfd9995a8318e329/File/zapodenepupizumife.pdf
- http://anatolianlgs.com/userfiles/file/degizavovebapakomupetepip.pdf
- https://ohligschlaeger-berger.de/wp-content/plugins/formcraft/file-upload/server/content/files/160bbe0479f0fa---fizunekavilepo.pdf
- https://www.foundationofhope.org/wp-content/plugins/formcraft/file-upload/server/content/files/1607f531f6bc1a---mujonisawonipivuremi.pdf
- https://hpsoft.shop/upload/files/84110715027.pdf
Embedded domains
- feedproxy.google.com
- primewestelectrical.com
- www.phonefixcomo.com
- sanitaerprofi.ch
- www.victorian-manor.co.za
- www.vibrationmonitoring.asia
- barudan.hk
- caribsplash.org
- acethamessecurity.co.uk
- www.1000ena.com
- adbadog.com
- compie.ru
- lifestyleufa.ru
- mediabandit.com
- www.sunarsurdurulebilir.com
- svenstavik.com
- zegabilisim.com
- aftaplan.com
- www.olympussverige.se
- stillwaterponies83.com
- gw73patriots.com
- anatolianlgs.com
- ohligschlaeger-berger.de
- www.foundationofhope.org
- hpsoft.shop
Embedded IP addresses
- 4.247.188.224
- 52.123.252.233
- 52.110.12.37
- 52.110.12.55
- 4.230.171.124
- 57.155.101.212
- 20.165.94.54
- 20.231.239.246
- 52.123.128.14
- 135.233.95.144
- 72.145.35.101
- 203.26.79.13
- 172.175.111.170
- 20.42.73.25
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report