MALICIOUS — 36f82544690df7f86e80e350db49faad845f5cfb73e3d41edf3163b971fe4f56
MALICIOUS — 36f82544690df7f86e80e350db49faad845f5cfb73e3d41edf3163b971fe4f56 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
36f82544690df7f86e80e350db49faad845f5cfb73e3d41edf3163b971fe4f56 - SHA-1:
2a1c79cc8d2b4b61dc390054037a8e1e55eb42b8 - MD5:
d51230b0af605b317a03cc1a0096fa38 - ssdeep:
1536:P3CDch4ojX0mEBM3H1yCDqNHlhQt7fWZ8We1jgayOpdJCNeklchWQpOCNUz:KqrAMFyCyO+ZSjW2JCkklcYCy - TLSH:
T1D839D0F3309BCD9C779B8F076AAB11699046D25C6122D5A011C9FA7CC43C6BDBB10E61 - Submitted as: 36f82544690df7f86e80e350db49faad845f5cfb73e3d41edf3163b971fe4f56
- File type: pdf · Size: 85474 bytes
- Verdict: malicious (98/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://sntaviator.ru/ckfinder/userfiles/files/90996282153.pdf, https://sidexsideaudio.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613cc386c4e48---15795705381.pdf, http://twtime.com/uploads/files/202109131509118895.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 14 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9769 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- c.pki.goog
- _dosvc._tcp.local
- ntp.ubuntu.com
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9?P1=1787953314&P2=404&P3=2&P4=hfgMXIHZBU1bSInX0hTWt7yJlsXayFqJ4Aj4sAgtsmza6YEvpGplUNnNHtF13WmkalljX3OVGi%2bGhcwRdWXrdQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
7b9c26e8d122177f87f3a023cc3c8c86cf6d61988c5ebbed1879665da11f65de - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\ac6cf2dc443a9a09e2fcf194be1e1900.png -
3c6ce2f73aa6e93582315463d0d5e8e2649d2bbbafefb347cf05c1ba0adc5dbf - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/cv9VXjIrmdE/uplcv?utm_term=cheat+engine+android+apk+no+root
- http://sntaviator.ru/ckfinder/userfiles/files/90996282153.pdf
- https://sidexsideaudio.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613cc386c4e48---15795705381.pdf
- http://twtime.com/uploads/files/202109131509118895.pdf
- https://ailani.org/wp-content/plugins/super-forms/uploads/php/files/676df736676223391ab91fffb11c516e/rivolavilawiwevamini.pdf
- http://primebrokeragetx.com/ckfinder/userfiles/files/ferotarituvo.pdf
- https://www.colegiodomus.com.br/js/ckfinder/userfiles/files/faxanidufavosalu.pdf
- http://debeleven.net/UserFiles/File/93578876972.pdf
- https://emotionalgift.youngzonejewelry.com/ckfinder/userfiles/files/14399442567.pdf
- https://petribax.nl/userfiles/file/27095136862.pdf
- http://valkexclusief.reviews/app/webroot/files/userfiles/files/95035251600.pdf
- http://andreagarciam.com/wp-content/plugins/formcraft/file-upload/server/content/files/16137190981f5b---40577081842.pdf
- http://mskabel.cz/UserFiles/File/20731362706.pdf
- http://www.stadion-zarya.ru/ckfinder/userfiles/files/rezugajitukomewubuj.pdf
- http://chukysovin.com/img-svc/files/nemarikarasafiko.pdf
- http://remontnoedelo.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1613b5099daa0a---86307471407.pdf
- http://kwong-cheong.com/userfiles/31599021454.pdf
- http://haai.org/upload/file/suwunotakikaloz.pdf
- https://festivaldelmaridaje.com/sgi_userfiles/userfiles/files/ruguzugodur.pdf
- http://aromaonly1.com/yamituki-n/uploads/files/86153701544.pdf
- https://weilmclainboiler.ca/fck_upload/file/95692386378.pdf
- https://vadihosting.com/calisma2/files/uploads/77502373458.pdf
- http://kantipursecurity.com/userfiles/file/61282157701.pdf
- https://www.opdrrustukalac.com/wp-content/plugins/formcraft/file-upload/server/content/files/161411397a1535---43507588133.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- sntaviator.ru
- sidexsideaudio.com
- twtime.com
- ailani.org
- primebrokeragetx.com
- www.colegiodomus.com.br
- debeleven.net
- emotionalgift.youngzonejewelry.com
- petribax.nl
- andreagarciam.com
- www.stadion-zarya.ru
- chukysovin.com
- remontnoedelo.ru
- kwong-cheong.com
- haai.org
- festivaldelmaridaje.com
- aromaonly1.com
- weilmclainboiler.ca
- vadihosting.com
- kantipursecurity.com
- www.opdrrustukalac.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 172.66.2.5
- 20.184.175.2
- 52.110.12.28
- 40.84.97.4
- 52.253.84.76
- 4.230.171.124
- 20.112.250.133
- 74.178.76.128
- 52.123.129.14
- 40.99.133.210
- 20.165.94.46
- 203.26.79.13
- 20.42.73.26
- 20.42.73.24
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report