MALICIOUS — 39bdbc59bc08c3d3d52eeb33b73e87e25c21eda17f6983492a4931f95140cae2
MALICIOUS — 39bdbc59bc08c3d3d52eeb33b73e87e25c21eda17f6983492a4931f95140cae2 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
39bdbc59bc08c3d3d52eeb33b73e87e25c21eda17f6983492a4931f95140cae2 - SHA-1:
26b0a05ef02d7c1a532731740e4e8b91a64294d6 - MD5:
1899f41f1bf4d73e0a475200d94c30ac - ssdeep:
1536:OCV5jlctjidVDxdrZ+pFT9nonPQhWDENAKG5c9IcxPXUUtskQ+D8jOf8D+ElC:nHjlCidlQJo6GiuchX2Of3 - TLSH:
T19238D0F36097ED8CBA999B437E5795BC6199C3947021DB20C088722CC9BC6BE7F51920 - Submitted as: 39bdbc59bc08c3d3d52eeb33b73e87e25c21eda17f6983492a4931f95140cae2
- File type: pdf · Size: 80612 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!1899F41F1BF4
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 16 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://b0cee159-9ce3-47d2-9452-de9e383f1b6b.filesusr.com/ugd/fac5c7_59733e77e6394100a719ec4f75591ab6.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://jottigo.ru/strik?utm_term=rune+magic+build+outward, https://b0cee159-9ce3-47d2-9452-de9e383f1b6b.filesusr.com/ugd/fac5c7_59733e77e6394100a719ec4f75591ab6.pdf?index=true, http://raisinshub.club/how_do_i_cancel_wall_street_journal_subscription9yzew.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9714 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\fce185a7692bde4980e0b0a1e6ac4aea.png -
27a11161b4cd7c0479f2e26bda5ee42382eac9375f4f1a53bd700fb407b68f26 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
b0d12435f8430c8bc4eca33c66d8d977e6fed18b86c107d1fd07515aa571ca1a - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://jottigo.ru/strik?utm_term=rune+magic+build+outward
- https://b0cee159-9ce3-47d2-9452-de9e383f1b6b.filesusr.com/ugd/fac5c7_59733e77e6394100a719ec4f75591ab6.pdf?index=true
- http://raisinshub.club/how_do_i_cancel_wall_street_journal_subscription9yzew.pdf
- https://6a543b89-810f-4a07-932c-4cc129fc401a.filesusr.com/ugd/1e5726_51650f1b8404490bbf5d990a72a7d9ac.pdf?index=true
- https://cdn-cms.f-static.net/uploads/4412158/normal_60267c82549f0.pdf
- https://c3438639-6a75-4920-aa4f-d1e0b619354f.filesusr.com/ugd/3be3a7_a3c13978a010418f9e105d908ffc1aff.pdf?index=true
- https://2903667b-e544-4972-ac7f-e5855aaa9b37.filesusr.com/ugd/2cc660_ec87b1ea3d3e490a81a72486184b8f23.pdf?index=true
- https://fopojikanerev.weebly.com/uploads/1/3/4/8/134888820/0036e371c09d7f.pdf
- http://mivetafo.epizy.com/american_gods_season_1_episode_7_review.pdf
- https://cdn-cms.f-static.net/uploads/4376380/normal_6052cced1d9ab.pdf
- https://gexuxufe.weebly.com/uploads/1/3/1/4/131406387/gamutoza.pdf
- https://muzuxagofonokow.weebly.com/uploads/1/3/1/4/131406885/592ca0ac8b2b993.pdf
- http://xoxejafomi.rf.gd/janujuwibobu.pdf
- https://mebedepubini.weebly.com/uploads/1/3/0/8/130813558/0214c69073694.pdf
- https://static.s123-cdn-static.com/uploads/4473384/normal_5fcaa3506a1cd.pdf
- http://help-violation.com/evicted_book_chapter_9_summary36hx3.pdf
- http://instapresent.site/tibepitodepevomasidhfp0.pdf
- http://bukaduxanob.epizy.com/90855306379.pdf
- http://afracheat6.xyz/tizivetazegapojowga8a.pdf
- http://generalmassage.online/anouilh_medeapwwtb.pdf
- http://kowisefofob.epizy.com/69337686412.pdf
- https://static.s123-cdn-static.com/uploads/4470832/normal_6008fa36bfbd4.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- jottigo.ru
- b0cee159-9ce3-47d2-9452-de9e383f1b6b.filesusr.com
- raisinshub.club
- 6a543b89-810f-4a07-932c-4cc129fc401a.filesusr.com
- cdn-cms.f-static.net
- c3438639-6a75-4920-aa4f-d1e0b619354f.filesusr.com
- 2903667b-e544-4972-ac7f-e5855aaa9b37.filesusr.com
- fopojikanerev.weebly.com
- mivetafo.epizy.com
- gexuxufe.weebly.com
- muzuxagofonokow.weebly.com
- mebedepubini.weebly.com
- static.s123-cdn-static.com
- help-violation.com
- instapresent.site
- bukaduxanob.epizy.com
- afracheat6.xyz
- generalmassage.online
- kowisefofob.epizy.com
- www.w3.org
- purl.org
- ns.adobe.com
- xoxejafomi.rf.gd
Embedded IP addresses
- 4.150.223.111
- 20.247.185.124
- 52.110.12.14
- 4.230.171.124
- 135.233.95.144
- 20.42.73.25
- 20.231.239.246
- 40.99.133.210
- 52.123.129.14
- 20.165.94.46
- 203.26.79.13
- 20.184.175.16
- 172.175.111.170
- 20.42.65.93
- 4.207.44.66
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report