MALICIOUS — 3f42a0599768447b325ffa445d4acd67a18647595d0c82427b7e36f2295cff17
MALICIOUS — 3f42a0599768447b325ffa445d4acd67a18647595d0c82427b7e36f2295cff17 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
3f42a0599768447b325ffa445d4acd67a18647595d0c82427b7e36f2295cff17 - SHA-1:
9d5d8ffcefcb1eb6ee139231523b9407be5ba1d9 - MD5:
1affd20460658255d86cf939d4b22a55 - ssdeep:
1536:10Oky55JJeRFw1Fwv5q+r81j+2eWIkJ4xb:WOmFw1O8gs+ZWI+2 - TLSH:
T1CE33CFE620E79D0C79CF6B03EE9A26AA459DE34CD236F794005C876E509C32E7C11947 - Submitted as: 3f42a0599768447b325ffa445d4acd67a18647595d0c82427b7e36f2295cff17
- File type: pdf · Size: 51812 bytes
- Verdict: malicious (96/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 25 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://3bcdeb60-9876-4d14-bc0a-1dd1632c647c.filesusr.com/ugd/16a96a_b729061f1ad1458aa370e8966f8fb2b0.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://baarspo.ru/aws?utm_term=detailed+summary+of+the+husband%2527s+secret, https://3bcdeb60-9876-4d14-bc0a-1dd1632c647c.filesusr.com/ugd/16a96a_b729061f1ad1458aa370e8966f8fb2b0.pdf?index=true, http://diwuvugu.epizy.com/pubavuwep.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (14 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
5705 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787844045&P2=404&P3=2&P4=e2PTvdxO86uL%2byP9gqX8do5l5bOMvruASox%2fhkde2g8ngnhMp9%2ftJ9JungEBP3DGSwqjHgtiaZcG1gZbYVbAbQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787844119&P2=404&P3=2&P4=GB2rHuG9v4UcawS%2for24NfchoSLPPrYPotaYBOqccXsQqnPYIEo3yAr8iwl95PyGgNATVy6WBmbTSNE2WLaIpA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787240761&P2=404&P3=2&P4=d04ZOwZw3X720J1KszHN7u%2bFWnFKQqPwAE6%2bgAbmJIDaAVTiFmqXEIqq3pBqVSG%2bkS3fYcoD8jmlUC0KE5Qknw%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
d33f9744db737f414b7d746fdb8a4cbaa28990744c196162ef4beeaef3712d10 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://baarspo.ru/aws?utm_term=detailed+summary+of+the+husband%2527s+secret
- https://3bcdeb60-9876-4d14-bc0a-1dd1632c647c.filesusr.com/ugd/16a96a_b729061f1ad1458aa370e8966f8fb2b0.pdf?index=true
- http://diwuvugu.epizy.com/pubavuwep.pdf
- https://likerediweraj.weebly.com/uploads/1/3/4/6/134691167/wawalinipudafoxiko.pdf
- https://xavamukunakupa.weebly.com/uploads/1/3/1/4/131437969/fetivefok-nubigipu-guxabalufatuwa-xijuruwemuloxa.pdf
- https://subogepaweb.weebly.com/uploads/1/3/2/3/132302814/1254345.pdf
- http://kuxoxulid.epizy.com/50971468751.pdf
- http://dulidezupo.rf.gd/67741000253.pdf
- https://b01ec662-dec5-4f54-b977-8708717d6054.filesusr.com/ugd/07e02c_320b33c6bd98459bba7728c2e9d51a9a.pdf?index=true
- https://lajogaful.weebly.com/uploads/1/3/4/4/134481829/wazovefarubeg-bilefix-lasozajejowezom-wivebu.pdf
- http://vonuvaxi.epizy.com/44911265724.pdf
- https://e8e87dc5-637d-47ba-9de6-e7d98d123d78.filesusr.com/ugd/a69a03_7ffa8f96bdb64cbfa1996454949ac7c3.pdf?index=true
- https://44eeb0f0-4dc9-4d8b-b3fd-cc7ace98e90e.filesusr.com/ugd/a083a1_5c9ad5bcefdf486c98502cd907eb287c.pdf?index=true
- https://bovabesizepin.weebly.com/uploads/1/3/1/3/131383515/wozifobevilabixuna.pdf
- https://cdn.sqhk.co/ragejeli/GxyDVha/durujivimomowogulubipor.pdf
- https://cdn.sqhk.co/mujawiru/hfghehe/yellow_cab_azuela_cove_menu.pdf
- https://cdn.sqhk.co/tuwesedujila/lYOihgi/fepujikililegikisunimijir.pdf
- https://jabasamivesapev.weebly.com/uploads/1/3/4/0/134041177/ea2cd.pdf
- https://02796127-04ec-4c85-b270-c6f7310ebb18.filesusr.com/ugd/ce0e6d_a52579b7daac4bcfb219deddaf9d4086.pdf?index=true
- https://cdn.sqhk.co/musutalivun/gegOsjb/lufuzakunobewusetafisi.pdf
- http://rexuworov.epizy.com/covid-19_news_los_angeles_ca.pdf
- https://namekabesomi.weebly.com/uploads/1/3/4/6/134668803/letumo-wulefosarebot-tifunoxubuf.pdf
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- baarspo.ru
- 3bcdeb60-9876-4d14-bc0a-1dd1632c647c.filesusr.com
- diwuvugu.epizy.com
- likerediweraj.weebly.com
- xavamukunakupa.weebly.com
- subogepaweb.weebly.com
- kuxoxulid.epizy.com
- b01ec662-dec5-4f54-b977-8708717d6054.filesusr.com
- lajogaful.weebly.com
- vonuvaxi.epizy.com
- e8e87dc5-637d-47ba-9de6-e7d98d123d78.filesusr.com
- 44eeb0f0-4dc9-4d8b-b3fd-cc7ace98e90e.filesusr.com
- bovabesizepin.weebly.com
- cdn.sqhk.co
- jabasamivesapev.weebly.com
- 02796127-04ec-4c85-b270-c6f7310ebb18.filesusr.com
- rexuworov.epizy.com
- namekabesomi.weebly.com
- dulidezupo.rf.gd
Embedded IP addresses
- 51.105.71.137
- 52.253.84.76
- 52.110.12.55
- 20.165.94.46
- 4.230.171.124
- 72.153.5.131
- 203.26.79.13
- 104.46.162.224
- 20.76.201.171
- 74.178.240.61
- 172.215.188.225
- 52.123.128.14
- 172.172.255.217
- 57.155.104.224
- 135.233.45.223
- 4.247.188.224
- 40.84.97.4
- 20.42.179.204
- 92.223.78.30
- 20.42.179.192
- 172.215.188.232
- 48.211.4.16
- 172.170.180.133
- 20.42.73.27
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report