MALICIOUS — 69cc3951dcd9519aefebe427db967940b5f3f1eb1a1e123b749bfc0528ae541d
MALICIOUS — 69cc3951dcd9519aefebe427db967940b5f3f1eb1a1e123b749bfc0528ae541d is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
69cc3951dcd9519aefebe427db967940b5f3f1eb1a1e123b749bfc0528ae541d - SHA-1:
c96ba186189449ced704a7b1f36e585a39a0e453 - MD5:
8ef01049cca5a696d6eed6670fd3729d - ssdeep:
1536:0AJ7ZsPNdLEgRt7ueWzXoOAF6Iq/9q/QM1dMxWGpOK32WFs7M9kWZnGdQ32uTueO:dVsPXYatXeXo96Iu9q/QMomKGHM9dnGn - TLSH:
T1E039D1E311E7DE4C7397CB43346602ECA44AEB8C6231E791048C7AAC95B867DBF00A41 - Submitted as: 69cc3951dcd9519aefebe427db967940b5f3f1eb1a1e123b749bfc0528ae541d
- File type: pdf · Size: 88137 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 19 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://iohrp.org/f_files/files/xizevedowerepan.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://philabc.ru/uplcv?utm_term=ejercicios+de+multiplicaciones+para+sexto+grado, http://victorylimo1.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b31e8c69d6d---nimolegawuwezetofajela.pdf, https://www.sudburyhighspeedinternet.ca/wp-content/plugins/super-forms/uploads/php/files/abb44eb99f4706875cc3bf98eef4b8bc/zedukowuxusapakaf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9843 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\e3073a49753d17353c5f4a4ca96fabaa.png -
a5d1ad50bbbaec933945d310c7e43d41f7e8dd3c82d8ac1ee1ee682731685583 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
75b23e94e4732667f5e7145504d51f1907e7d8e67746291f351fcfcfa1025a65 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://philabc.ru/uplcv?utm_term=ejercicios+de+multiplicaciones+para+sexto+grado
- http://victorylimo1.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b31e8c69d6d---nimolegawuwezetofajela.pdf
- https://www.sudburyhighspeedinternet.ca/wp-content/plugins/super-forms/uploads/php/files/abb44eb99f4706875cc3bf98eef4b8bc/zedukowuxusapakaf.pdf
- https://egf.tw/test2/images/file/zulolekozaxebabapofelir.pdf
- https://www.die-umzugsfabrik.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b12fd2629fd---55505041289.pdf
- https://iohrp.org/f_files/files/xizevedowerepan.pdf
- http://exoticland.bg/upload/files/files/71252243451.pdf
- http://izeninfo.net/admin/upload/files/vejesenaburamizuna.pdf
- http://macphersonproperties.com/clients/876251/File/90984734603.pdf
- https://gastrotest.co/ckfinder/userfiles/files/22002239002.pdf
- https://noks.cz/wp-content/plugins/formcraft/file-upload/server/content/files/160c6e6a5105e0---laronabisapurekozonawu.pdf
- http://ajivikafinance.com/userfiles/file/98649646076.pdf
- http://www.homefacelifters.com/wp-content/plugins/super-forms/uploads/php/files/4e832d5f4774f952a0757646bbcccad0/64216469648.pdf
- https://1sis.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bb811fac085---befotov.pdf
- https://www.helpforbusymums.com/wp-content/plugins/super-forms/uploads/php/files/5e9b0438dec2b358d47654ee0851f0cf/65716645208.pdf
- https://fid-data.fr/app/webroot/uploaderfiles/farukisimixurikuziga.pdf
- http://ar-intl.net/wp-content/plugins/super-forms/uploads/php/files/thbhve5rq106n1k9t2tkpnu3s3/xusofusujugupebuzutapekan.pdf
- http://mko-yug.ru/wp-content/plugins/super-forms/uploads/php/files/9aacfbfcb0fa23972c41579e12aa893b/88283050299.pdf
- https://menu2uplus.com/images/file/99395801114.pdf
- http://brenna-ski.pl/userfiles/file/99137427403.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- philabc.ru
- victorylimo1.com
- www.sudburyhighspeedinternet.ca
- egf.tw
- www.die-umzugsfabrik.com
- iohrp.org
- izeninfo.net
- macphersonproperties.com
- gastrotest.co
- ajivikafinance.com
- www.homefacelifters.com
- 1sis.com
- www.helpforbusymums.com
- fid-data.fr
- ar-intl.net
- mko-yug.ru
- menu2uplus.com
- brenna-ski.pl
- www.w3.org
- purl.org
- ns.adobe.com
- exoticland.bg
- noks.cz
Embedded IP addresses
- 20.184.175.14
- 52.123.252.233
- 52.110.12.11
- 52.230.59.222
- 4.230.171.124
- 52.168.112.67
- 20.236.44.162
- 20.165.94.63
- 74.178.240.61
- 52.123.128.14
- 135.233.45.221
- 52.123.252.212
- 72.153.5.96
- 203.26.79.13
- 20.184.175.8
- 92.223.78.30
- 20.184.175.23
- 4.150.223.96
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report