MALICIOUS — 4a77d0f41a8003a85899bf0a546bc3f9181343212350ba9b411b55682733d24d
MALICIOUS — 4a77d0f41a8003a85899bf0a546bc3f9181343212350ba9b411b55682733d24d is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
4a77d0f41a8003a85899bf0a546bc3f9181343212350ba9b411b55682733d24d - SHA-1:
475bd573484a7e8042d6343156dd5e636086f451 - MD5:
61a6940cfd2b86292f0f51f3f901b7da - ssdeep:
1536:BeOMTHYrFh0Yb0M0a8Yr1tvqVlhCADKVatO9CBZOvCU6Hchql7j7oZX:4TEoMfFr1tk5f4YZ+CUJhqZj7g - TLSH:
T16A37D0F73167EECC6AC74B936AB705DC648B96C970329B445858B71CC5382AE7F00922 - Submitted as: 4a77d0f41a8003a85899bf0a546bc3f9181343212350ba9b411b55682733d24d
- File type: pdf · Size: 75947 bytes
- Verdict: malicious (98/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!61A6940CFD2B
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/adfeb8d6-04bf-4da3-9f45-a53bf3ec4e0b/tricaster_460_manual.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 16 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://medvor.ru/pbw?utm_term=les+territoires+dans+la+mondialisation+terminale+es+fiche, https://gesunewa.weebly.com/uploads/1/3/1/4/131438127/wurikedaxa-gagut-rumisiragumukaj-dulodorad.pdf, https://uploads.strikinglycdn.com/files/adfeb8d6-04bf-4da3-9f45-a53bf3ec4e0b/tricaster_460_manual.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (7 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9666 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787922964&P2=404&P3=2&P4=Ved18HWdWGPYEwStQh8hId2uWJPotDmB8zdF4R4aNR9mCI3joq9RfQRbEJHzQ3FxDVq%2baasDFkYI5i1gTLxLNQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787923038&P2=404&P3=2&P4=CUt6rh%2bs7dR1psLya2vpZL9tlLhdwe4t3CgLkn%2bgRJgeZRb22ZfPWMl2ubH6CH1sl8f27kfMm8OMci7MPgJ4Tg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
6efc6e57a8c57da28d15c2d6c9fe356c2213c37566ca8384da305be991b704fb - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\ae946f0c742270984213f4a370e9711a.png -
5d223e088442c04a36df5ebbb64f88b7a8d7258da946754fd48370af8fb1f147 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://medvor.ru/pbw?utm_term=les+territoires+dans+la+mondialisation+terminale+es+fiche
- https://gesunewa.weebly.com/uploads/1/3/1/4/131438127/wurikedaxa-gagut-rumisiragumukaj-dulodorad.pdf
- https://uploads.strikinglycdn.com/files/adfeb8d6-04bf-4da3-9f45-a53bf3ec4e0b/tricaster_460_manual.pdf
- https://munibejexa.weebly.com/uploads/1/3/1/4/131414516/petofaxomiguzi-jeripinuz-tidijuna-daguwuk.pdf
- https://velalozelo.weebly.com/uploads/1/3/4/4/134498802/9013552.pdf
- https://vumokaxizojomij.weebly.com/uploads/1/3/2/6/132680848/5809270.pdf
- https://zadobixif.weebly.com/uploads/1/3/1/4/131437920/6c6f0d44.pdf
- http://wiliser.pbworks.com/f/74723824957.pdf
- https://uploads.strikinglycdn.com/files/a0f95528-42ab-4a59-962a-7bcc9e7d4d47/how_to_put_chain_back_on_poulan_chainsaw.pdf
- https://morinuzarisifuf.weebly.com/uploads/1/3/4/2/134234593/muvomo-fajas-pomitafadela.pdf
- https://samazixudoreput.weebly.com/uploads/1/3/2/6/132681586/nadupi.pdf
- https://uploads.strikinglycdn.com/files/d8ded8ce-e147-4d7d-ad23-84a582b24fc6/muri_alfredo_palacios_estilista_biografia.pdf
- https://pisubamu.weebly.com/uploads/1/3/0/7/130740412/9255532.pdf
- https://uploads.strikinglycdn.com/files/d8919212-9a96-467b-b839-b6892918970f/39432157199.pdf
- https://gekuxufetog.weebly.com/uploads/1/3/1/3/131384115/bokezifore_giwoganasiko.pdf
- https://libadelalisam.weebly.com/uploads/1/3/4/5/134579317/bomigavo.pdf
- https://woxopipuwesubaj.weebly.com/uploads/1/3/1/4/131453061/3340328.pdf
- https://detaxotipag.weebly.com/uploads/1/3/4/7/134730838/2448920.pdf
- http://negaboxa.pbworks.com/f/mipenirokiperoga.pdf
- https://kujepilam.weebly.com/uploads/1/3/5/3/135343620/rupalo_meruladapewato_tagumowipar_ximugororawatiz.pdf
- https://uploads.strikinglycdn.com/files/0515277c-18a1-4f2d-a466-6a35c636c17d/bakojif.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- medvor.ru
- gesunewa.weebly.com
- uploads.strikinglycdn.com
- munibejexa.weebly.com
- velalozelo.weebly.com
- vumokaxizojomij.weebly.com
- zadobixif.weebly.com
- wiliser.pbworks.com
- morinuzarisifuf.weebly.com
- samazixudoreput.weebly.com
- pisubamu.weebly.com
- gekuxufetog.weebly.com
- libadelalisam.weebly.com
- woxopipuwesubaj.weebly.com
- detaxotipag.weebly.com
- negaboxa.pbworks.com
- kujepilam.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 57.155.101.212
- 52.123.252.192
- 85.210.196.11
- 4.230.171.124
- 20.247.184.142
- 135.232.92.137
- 20.42.73.30
- 20.76.201.171
- 52.123.252.218
- 74.179.71.159
- 52.123.128.14
- 72.153.5.138
- 20.184.175.12
- 203.26.79.13
- 4.150.223.114
- 172.170.180.133
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report