MALICIOUS — 3ef984576f3e5cfdf5a812e8ac8439b3f7c56f894eb6f97db8d06f0127325218
MALICIOUS — 3ef984576f3e5cfdf5a812e8ac8439b3f7c56f894eb6f97db8d06f0127325218 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
3ef984576f3e5cfdf5a812e8ac8439b3f7c56f894eb6f97db8d06f0127325218 - SHA-1:
1a62364b5281608339af20eaaecd3ee1a3ab2b91 - MD5:
7704cb3f36065c6558542268580224a8 - ssdeep:
3072:03ZbBsOyrNPmgCILLMsWDUjq6NZxbzMCZ2H3xg7MAtYtiNJBJ7p:QBB2xmgCISDUjzNbvtiTAytiNJBJ7p - TLSH:
T1B33BE1F320DBEE4C364D9F436D9621BD6589E7C96230CD6140CC72ACA87C5BEAE04651 - Submitted as: 3ef984576f3e5cfdf5a812e8ac8439b3f7c56f894eb6f97db8d06f0127325218
- File type: pdf · Size: 106363 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 12 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: http://thegioixedap.net/upload/files/13373070118.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://oniceh.ru/uplcv?utm_term=how+do+you+screenshot+on+snapchat+without+the+person+knowing, https://decoveinvestment.com/userfiles/file/dizurolewodeduz.pdf, https://www.shopveriamici.com/wp-content/plugins/super-forms/uploads/php/files/0fbtsk72pfm1ipnnmte8quj6os/95005982973.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9701 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- _ipps._tcp.local
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\7041c9db5e678c4969bc3c4c7046b683.png -
cbda27497fcffd9053b192ea42805c9ef3dacd55de1009ec769e82d95ba9eaf2 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
388e5a0463484dc741ad3ad91f4ef9ab4c32fef96e855d0b68c075f3e54cd321 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://oniceh.ru/uplcv?utm_term=how+do+you+screenshot+on+snapchat+without+the+person+knowing
- https://decoveinvestment.com/userfiles/file/dizurolewodeduz.pdf
- https://www.shopveriamici.com/wp-content/plugins/super-forms/uploads/php/files/0fbtsk72pfm1ipnnmte8quj6os/95005982973.pdf
- https://zzwgjx.com/d/files/1505190651.pdf
- http://h-p-n.fr/catalogue_dynamique/file/dugujufuwozanageto.pdf
- https://coebmsf.com/userfiles/file/33717304518.pdf
- http://thegioixedap.net/upload/files/13373070118.pdf
- https://ljlconst.com/admin/images/file/lijirimemikalewegom.pdf
- http://wangyiphk.com/userfiles/56807587713.pdf
- http://jockmurray.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613417c282cf5---samigogavafu.pdf
- http://www.neslihanonur.com/wp-content/plugins/super-forms/uploads/php/files/e4635525de903197033a61b1aa57be5c/nopoxewevorosel.pdf
- http://tropo-design.com/ckfinder/userfiles/files/55327282660.pdf
- http://geometramaurotozzi.it/userfiles/files/64178926573.pdf
- http://arcenevents.nl/site/upload/files/14717952332.pdf
- http://faithleader.org/js/ckfinder/userfiles/files/vimas.pdf
- https://airflow-skateboards.com/userfiles/files/repemeguzijodufanug.pdf
- http://allineers.netlovestories.com/upload/files/13148968860.pdf
- http://hvpeds.com/upload/contents/file/59470657924.pdf
- http://edu-family72.ru/content/images/uploads/file/begimewawuru.pdf
- http://apsara.ru/userfiles/file/86746881202.pdf
- https://levin-dent.ru/wp-content/plugins/super-forms/uploads/php/files/58dd41b9e483c23b2dbe328948a53300/1163984833.pdf
- https://adlinefor.com/home/webagen/public_html/korn/data/file/64520481423.pdf
- https://indikino.com/ckfinder/userfiles/files/katuxiveve.pdf
- http://ozdesignhouse.com/app/webroot/uploads/files/mubarufowigubegudi.pdf
- http://fcv-bo.org/data/fcv-bo/userfiles/file/gazakaluwofisav.pdf
Embedded domains
- oniceh.ru
- decoveinvestment.com
- www.shopveriamici.com
- zzwgjx.com
- h-p-n.fr
- coebmsf.com
- thegioixedap.net
- ljlconst.com
- wangyiphk.com
- jockmurray.com
- www.neslihanonur.com
- tropo-design.com
- geometramaurotozzi.it
- arcenevents.nl
- faithleader.org
- airflow-skateboards.com
- allineers.netlovestories.com
- hvpeds.com
- edu-family72.ru
- apsara.ru
- levin-dent.ru
- adlinefor.com
- indikino.com
- ozdesignhouse.com
- fcv-bo.org
Embedded IP addresses
- 20.184.175.9
- 20.42.179.204
- 4.230.171.124
- 135.233.95.135
- 74.178.240.61
- 74.179.77.204
- 52.123.128.14
- 40.99.133.242
- 135.232.92.34
- 203.26.79.13
- 20.184.175.0
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report