MALICIOUS — 16217022340.pdf
MALICIOUS — 16217022340.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
5d0d4ca1c83b0d0efc48758c89e8c4719b5112a80acb8ebe3b91589e1edd5af4 - SHA-1:
ab2a5440a7d2da7db7821ea4eaf76368c9b24c73 - MD5:
c2ff8faea4fa9e3e1597e591dd6cad40 - ssdeep:
1536:LDbIJyli3679ToAIFIxsGltCiHcDCFZoD71RKZZUWm8xHDWGpOG2G0H1:0J2e67BoAIFN4tCO3ZodIj68FYGl6 - TLSH:
T1CA39C0F36197DF0C774B5F83A8E61268608ED7487172EA504488B67C8ABC5BDBF04650 - Submitted as: 16217022340.pdf
- File type: pdf · Size: 89324 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 18 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://lion-trading.co.uk/wp-content/plugins/super-forms/uploads/php/files/a05jjhl71pfeb66ni3d4allrm0/96346441237.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://proff-doors.ru/wp-content/plugins/super-forms/uploads/php/files/b862d0e0b42741b271ae737f402bb91b/faxekeparix.pdf, https://bf-pomosch.ru/wp-content/plugins/super-forms/uploads/php/files/h7ks4kejuo11315hqdcvb1lb07/dukotup.pdf, http://urjabatteries.in/userfiles/file/lezajude.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9770 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787778679&P2=404&P3=2&P4=aXtmH%2fGjeRvwyR72HlLBoDsuDOXftJlakRwImrBVOEhm1fMxEhahH8uKCShXUodrZslR7FDVn1d%2fL9OO9JSiEw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787778744&P2=404&P3=2&P4=HVuy0bUyRx1TNrEJZKllBb5AGg4D4LmyO6lozBAw1XTI%2b4T7WacnTNuCFJ8kPrPjKKiSc57nE%2bzwYK%2fFJanrAQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787175400&P2=404&P3=2&P4=D8DogXHhZQqIAp0FSbmXPy%2fP%2fszqu8rlOx%2bgvJL0RTHgziiz8oV4l7sYaxox63XygG2KrjqaTpnYfbvcOclqlg%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\f09f21d6206ba23e66d420f36a4b55e4.png -
fab6b562a916fdf7963c1d7d6c87bf2fb4024b8633861cd03d1c8c9cc681032e - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
f5c994d337b689bb99fc0775cb78b2cdda676833abc0fe38c660485e4af923c8 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/zMnd8XtcwSM/uplcv?utm_term=how+to+use+amiibo+with+phone
- https://proff-doors.ru/wp-content/plugins/super-forms/uploads/php/files/b862d0e0b42741b271ae737f402bb91b/faxekeparix.pdf
- https://bf-pomosch.ru/wp-content/plugins/super-forms/uploads/php/files/h7ks4kejuo11315hqdcvb1lb07/dukotup.pdf
- http://urjabatteries.in/userfiles/file/lezajude.pdf
- http://bamt.be/wp-content/plugins/formcraft/file-upload/server/content/files/1608e3786d0cb3---fajunozomifagajaputilag.pdf
- https://reparation-mobile.net/userfiles/file/56528920072.pdf
- https://www.sharpeningfactory.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607dd7c41ff01---nunelugudaxotis.pdf
- http://stroynerud-sm.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1607fb2afef6d5---55485708059.pdf
- https://menuiserie-sainte-anne.fr/userfiles/file/32615505130.pdf
- https://lion-trading.co.uk/wp-content/plugins/super-forms/uploads/php/files/a05jjhl71pfeb66ni3d4allrm0/96346441237.pdf
- http://www.brennholz-heinlein.de/wp-content/plugins/formcraft/file-upload/server/content/files/160a41ce4e3b24---62900770124.pdf
- http://www.holderit.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a9629c6b92e---teketiromotebub.pdf
- https://www.unicodesystems.com/wp-content/plugins/super-forms/uploads/php/files/hb3ljg4q5eu68q5jvfau86rpr7/jagelokigabawetobavevi.pdf
- https://naoshima-habitant.com/66741277762.pdf
- https://cedarcreeksauce.com/wp-content/plugins/super-forms/uploads/php/files/d6b45a6fdee03ebbe94f24088aaa1b19/30835484835.pdf
- http://closehorses.com/userfiles/file/zijezuvariwilijiro.pdf
- https://ontime-taxi.kg/wp-content/plugins/super-forms/uploads/php/files/495126960799699610a2854e992e0e5e/zexifedoridipobax.pdf
- http://africanhairbraidingsalon.com/userfiles/file/kusevekijexuguvuwusegeju.pdf
- http://jfe.hk/userfiles/83122210371.pdf
- https://ises.ca/phpsites/vertical_living/uploads/file/nusinuravufeliv.pdf
- https://rrvchefs.com/wp-content/plugins/super-forms/uploads/php/files/5329fc3b206382bacc75628efe9d7d5c/33463781841.pdf
- https://norservis.cz/files/files/punasasapulonajenodemix.pdf
- http://orderkai.com/uploads/files/madudawevot.pdf
- https://www.ogblfrontaliers.fr/wp-content/plugins/super-forms/uploads/php/files/da6mluc3g5b93rcm5f3lnn2mm2/begoridufeni.pdf
- https://uaqbakery.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f3e2260b19---27923392774.pdf
Embedded domains
- feedproxy.google.com
- proff-doors.ru
- bf-pomosch.ru
- urjabatteries.in
- bamt.be
- reparation-mobile.net
- www.sharpeningfactory.com
- stroynerud-sm.ru
- menuiserie-sainte-anne.fr
- lion-trading.co.uk
- www.brennholz-heinlein.de
- www.holderit.com
- www.unicodesystems.com
- naoshima-habitant.com
- cedarcreeksauce.com
- closehorses.com
- africanhairbraidingsalon.com
- jfe.hk
- ises.ca
- rrvchefs.com
- orderkai.com
- www.ogblfrontaliers.fr
- uaqbakery.com
- www.w3.org
- purl.org
Embedded IP addresses
- 20.42.73.24
- 52.123.252.202
- 52.110.12.20
- 57.155.104.224
- 4.230.171.124
- 52.123.252.216
- 135.233.95.80
- 20.247.185.124
- 72.145.35.103
- 203.26.79.13
- 135.233.95.135
- 20.165.94.63
- 20.42.65.91
- 52.123.252.213
- 52.123.128.14
- 40.99.133.242
- 85.210.196.11
- 52.168.117.168
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report