MALICIOUS — 432191f4d948e06cdfe92d1997b458ab5d33eb330a2f837d8c2d968963210799
MALICIOUS — 432191f4d948e06cdfe92d1997b458ab5d33eb330a2f837d8c2d968963210799 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
432191f4d948e06cdfe92d1997b458ab5d33eb330a2f837d8c2d968963210799 - SHA-1:
f99330e52c70fc817248423d08901ea77c1dab9f - MD5:
f5c7bb99e3ee07ddeaecd5750d5ec105 - ssdeep:
1536:GNE8Qhqimh9kujtVgFgUxqEhgnuQa8VThmyiewJlGWwjpiE9bCITWXpO/KDr:r7qim/kujmgSq4gnuetmDJluViELF/s - TLSH:
T1A938C1F321CBDD8C7A875F4369EA11A99046E74C72329B90404CF36C99BC9BD7E40A51 - Submitted as: 432191f4d948e06cdfe92d1997b458ab5d33eb330a2f837d8c2d968963210799
- File type: pdf · Size: 78406 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 22 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://ta-taiwan.com/app/webroot/userfiles/files/zulimumoxoba.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://simkoongschool.com/uploads/editer/files/1503468647.pdf, http://pokebarslo.com/uploads/files/7419077786.pdf, https://kovrdom.ru/sites/all/sites/default/files/file/ligubobevobivo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9776 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787847944&P2=404&P3=2&P4=el620qqOc49O8kVRgH%2fzW5huzi%2fCncFHgw29frmZ%2bZUFr%2b7v6Md8CXyya4ohaiW5ORNUxc%2b%2bavgmkRI0JNsUbA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\606d1b3cec9484cafe50723b578f7b60.png -
913c1cf042562b48d510c17d9c56a7883c4cb423f1bd64b35242d4328ab839e1 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
0dff49fe80a711dc64a6a209a779332ae61d594da4faea9b8412385e2a9d8815 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/3CAf4wW3hvY/uplcv?utm_term=wattage+calculator+pc+build
- http://simkoongschool.com/uploads/editer/files/1503468647.pdf
- http://pokebarslo.com/uploads/files/7419077786.pdf
- https://kovrdom.ru/sites/all/sites/default/files/file/ligubobevobivo.pdf
- https://777mto.info/contents/files/kanuvetet.pdf
- http://twilaw.com/files/files/33597907507.pdf
- http://qapoll.com/2015/vat/upload/files/37881562864.pdf
- https://interior-mark.com/ckfinder/userfiles/files/zexodefatup.pdf
- https://www.web2business.pt/wp-content/plugins/formcraft/file-upload/server/content/files/16140aecbe31b9---50344549914.pdf
- http://jsqnchem.com/upload/files/54637780438.pdf
- https://ta-taiwan.com/app/webroot/userfiles/files/zulimumoxoba.pdf
- https://moma-restaurant.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613b556eaa222---91328852189.pdf
- http://compow.net/ckfinder/userfiles/files/gadexizeleluwewivik.pdf
- https://aquatrustfina.com/userfiles/file/bilulebotawofepifuxat.pdf
- https://rubenoferro.com/userfiles/file/mirokalasifa.pdf
- http://lookupagency.es/wp-content/plugins/formcraft/file-upload/server/content/files/161409ad63ae1a---55891611166.pdf
- http://modelseafarm.com/kweb/ckfinder/userfiles/files/18137409094.pdf
- http://sanarina-coaching.de/ckfinder/userfiles/files/pododevoxawemujegix.pdf
- https://projetounificado.com/uploads/files/78609837417.pdf
- http://ebiocell.com/uploadfile/file///2021090321455664.pdf
- http://roosprommenschenckelfoundation.nl/userfiles/file/26774009807.pdf
- https://konferencii.ru/js/ckfinder/userfiles/files/fexovawu.pdf
- http://www.mtpartnersfl.com/wp-content/plugins/formcraft/file-upload/server/content/files/161420d8fdc258---23195148754.pdf
- http://nikkenj.com/userfiles/file/60116084793.pdf
- https://soenen-pneus.com/upload/file/lavuzoxanumizoroniwebeb.pdf
Embedded domains
- feedproxy.google.com
- simkoongschool.com
- pokebarslo.com
- kovrdom.ru
- 777mto.info
- twilaw.com
- qapoll.com
- interior-mark.com
- jsqnchem.com
- ta-taiwan.com
- moma-restaurant.com
- compow.net
- aquatrustfina.com
- rubenoferro.com
- lookupagency.es
- modelseafarm.com
- sanarina-coaching.de
- projetounificado.com
- ebiocell.com
- roosprommenschenckelfoundation.nl
- konferencii.ru
- www.mtpartnersfl.com
- nikkenj.com
- soenen-pneus.com
- inbeeldt.nl
Embedded IP addresses
- 135.234.160.245
- 52.123.252.213
- 4.144.132.223
- 52.110.12.30
- 4.230.171.124
- 74.179.71.159
- 72.145.35.105
- 203.26.79.13
- 172.66.2.5
- 135.232.92.97
- 74.179.77.204
- 20.236.44.162
- 40.99.133.210
- 20.184.175.9
- 52.123.128.14
- 40.99.134.2
- 74.178.76.128
- 20.42.73.25
- 92.223.78.30
- 4.150.223.111
- 48.200.63.27
- 51.105.71.137
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report