MALICIOUS — 6f475410592bd1404dcc93d3e1ab7cb4b9563eb2f23b7b5e1978aa698a73b314
MALICIOUS — 6f475410592bd1404dcc93d3e1ab7cb4b9563eb2f23b7b5e1978aa698a73b314 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
6f475410592bd1404dcc93d3e1ab7cb4b9563eb2f23b7b5e1978aa698a73b314 - SHA-1:
af87bd759c278ef2c25b0bca6327405ec52d9054 - MD5:
f879e0a56bbcfcddfa3315bd669ea4d4 - ssdeep:
1536:fgZ4rscbuFQKMX0m9fqJhltqKh4K+glnjiXxbpqGKVgW:4irMGXvqJpCfglnU5EGK/ - TLSH:
T1CE37C0F3B1DBFCCC7A6E4F036AA7656CA4C4D28862365A411488771C94BC77E3E00962 - Submitted as: 6f475410592bd1404dcc93d3e1ab7cb4b9563eb2f23b7b5e1978aa698a73b314
- File type: pdf · Size: 70797 bytes
- Verdict: malicious (98/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!F879E0A56BBC
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/fcc8eeac-1049-45e1-8462-dfbfa0d3ed24/deepak_chopra_seven_spiritual_laws_for_parents.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 15 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://bologen.ru/strik?utm_term=go+math+reteach+book+grade+5+answer+key, https://uploads.strikinglycdn.com/files/fcc8eeac-1049-45e1-8462-dfbfa0d3ed24/deepak_chopra_seven_spiritual_laws_for_parents.pdf, https://uploads.strikinglycdn.com/files/74cecacd-b597-46ef-bb72-1eac0bb489d5/befusujomovekalijawexiluf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (14 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9667 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787904083&P2=404&P3=2&P4=V67kfPV%2fMDbB%2fHkZq4tIs5H8JAXCqdXEDBAkI7UlmNxpvPHHQfymgD00ENPQl2OKgx26SV8XPiBizXw0M8Yo%2bg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787904101&P2=404&P3=2&P4=bbLoP4yWcWvhqrUi8jX%2btHHa0TOz%2fqAqK2zYNaECqUPArgmkmQ%2b4k2XwF1zyt1KdJqES1nSYuB4S4z7dvE4IQg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787300879&P2=404&P3=2&P4=XUEVwYCc%2bjmKzRHWdispkwchfoZysaCKfC2S3O4rBKZM4jjwSYb1gvVmN27LpfWC74Gb1J8cbitmba09lldTkg%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\fc6b24c48959f0869485838038872587.png -
989170c12d6f73a6b4d94505ea5607646405c8927d70bd952bcb31ffce2ee174 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
9f669053db2624e50edd1239297a3a3b46c089c4235b7bf2877f362fa4b44bc3 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://bologen.ru/strik?utm_term=go+math+reteach+book+grade+5+answer+key
- https://s3.amazonaws.com/mejawiwomak/78020554465.pdf
- https://uploads.strikinglycdn.com/files/fcc8eeac-1049-45e1-8462-dfbfa0d3ed24/deepak_chopra_seven_spiritual_laws_for_parents.pdf
- https://uploads.strikinglycdn.com/files/74cecacd-b597-46ef-bb72-1eac0bb489d5/befusujomovekalijawexiluf.pdf
- https://be9c8297-50e9-4ec8-be22-7cc4068ef96a.filesusr.com/ugd/fc3b0b_62a2c3448c4f4cabb19cffeb67e105e1.pdf?index=true
- https://e4fb9bf1-a3d6-4767-9bf2-2a1021e5dc09.filesusr.com/ugd/53cfc7_5d91454ae0b94a4399cb60d839fca99d.pdf?index=true
- http://nojupaven.rf.gd/dynasty_warriors_4_items_guide.pdf
- https://s3.amazonaws.com/lijopavexanuse/gaziwasuna.pdf
- http://tudugir.atwebpages.com/tajopekudesux.pdf
- https://s3.amazonaws.com/jemisajoda/panasurudibowufatogaduv.pdf
- https://3d7c42e8-cad9-4196-8f3c-0f210fd97588.filesusr.com/ugd/1b7c00_58ac634db9c24803965367c6da7e1d50.pdf?index=true
- https://s3.amazonaws.com/sisaxu/jejugugamuf.pdf
- http://mapotilij.mygamesonline.org/international_business_the_challenges_of_globalization_free.pdf
- http://dojopugoput.epizy.com/20517145206.pdf
- http://minetijixe.rf.gd/kikapifuj.pdf
- http://kelimap.mywebcommunity.org/wd_my_cloud_software.pdf
- https://s3.amazonaws.com/nigimul/86557819253.pdf
- http://tejasatobes.medianewsonline.com/kixijuwawomebirabajuweli.pdf
- https://s3.amazonaws.com/dixaleko/english_grammar_worksheets_for_class_3_cbse.pdf
- http://fumuroruzej.medianewsonline.com/53652562570.pdf
- https://s3.amazonaws.com/litunux/kejakekozu.pdf
- https://uploads.strikinglycdn.com/files/1405767e-2032-4528-967c-a411684f7c17/how_to_measure_a_dog_for_a_waterproof_coat.pdf
- http://xukaneteris.epizy.com/apptoko_free_fire.pdf
- http://nijibegosovatiz.iblogger.org/select_city_walk_store_guide.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- bologen.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- be9c8297-50e9-4ec8-be22-7cc4068ef96a.filesusr.com
- e4fb9bf1-a3d6-4767-9bf2-2a1021e5dc09.filesusr.com
- tudugir.atwebpages.com
- 3d7c42e8-cad9-4196-8f3c-0f210fd97588.filesusr.com
- mapotilij.mygamesonline.org
- dojopugoput.epizy.com
- kelimap.mywebcommunity.org
- tejasatobes.medianewsonline.com
- fumuroruzej.medianewsonline.com
- xukaneteris.epizy.com
- nijibegosovatiz.iblogger.org
- www.w3.org
- purl.org
- ns.adobe.com
- nojupaven.rf.gd
- minetijixe.rf.gd
Embedded IP addresses
- 172.215.188.225
- 20.42.179.192
- 52.110.12.8
- 40.84.97.4
- 4.230.171.124
- 20.165.94.63
- 74.178.240.51
- 52.123.129.14
- 135.234.160.246
- 203.26.79.13
- 74.178.76.44
- 20.42.65.88
- 4.209.250.170
- 20.42.65.93
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report