MALICIOUS — 751f9a2b501597be56f7d866137e6c1d29e3baf93cd1c0f44601fc4cc50cc393
MALICIOUS — 751f9a2b501597be56f7d866137e6c1d29e3baf93cd1c0f44601fc4cc50cc393 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
751f9a2b501597be56f7d866137e6c1d29e3baf93cd1c0f44601fc4cc50cc393 - SHA-1:
a922aface52e94c8b87de17440fabde2cd457ec6 - MD5:
f1cbe463360e6c760472ec1128d75829 - ssdeep:
1536:QHedt2oz//lJ6fnkaLUjgPlixn8NOE7jX4Mok7HbtjKB:weJ/d4PioJ7j4MlzbtE - TLSH:
T10E39E0F3614BED4CB9D69F43AD6225546088B5487133EEA19448BA7DC8F81BFBE20D10 - Submitted as: 751f9a2b501597be56f7d866137e6c1d29e3baf93cd1c0f44601fc4cc50cc393
- File type: pdf · Size: 85009 bytes
- Verdict: malicious (98/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!F1CBE463360E
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4470399/normal_5fcc08efc70cf.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 14 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://dugedepap.ru/strik?utm_term=hp+elitedesk+800+g1+drivers+windows+7+32+bit, https://88966db1-4a83-4446-b941-f65022a6235f.filesusr.com/ugd/928e0f_98461e6406694a589f4504c5aa3074a3.pdf?index=true, https://bomaripuxizidul.weebly.com/uploads/1/3/4/9/134901287/63de8003240e39a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (14 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9726 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\9399ffb5ad1f79e4e7e52d6a4125358a.png -
d12db21f7ccec76f4a55aec200b500e09dbb0629a35a0261694cdfff646b5b39 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
67048aa925799a925707f867bf482488dae2edade86dc5bb65f5a23316e10b2a - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://dugedepap.ru/strik?utm_term=hp+elitedesk+800+g1+drivers+windows+7+32+bit
- https://88966db1-4a83-4446-b941-f65022a6235f.filesusr.com/ugd/928e0f_98461e6406694a589f4504c5aa3074a3.pdf?index=true
- https://bomaripuxizidul.weebly.com/uploads/1/3/4/9/134901287/63de8003240e39a.pdf
- https://cdn.sqhk.co/gelowidabik/jOjjijb/runalifuzesudojubolatidi.pdf
- https://static.s123-cdn-static.com/uploads/4470399/normal_5fcc08efc70cf.pdf
- https://cdn-cms.f-static.net/uploads/4369525/normal_5fd7a2388af09.pdf
- https://459ec6dd-5b69-4322-a182-74abbfaa0e48.filesusr.com/ugd/221eaa_1cbb74efa1304ecb8ebe1ced8b7e47d6.pdf?index=true
- https://70010cfe-69b1-4fe9-a336-bdfe2418dc1e.filesusr.com/ugd/f1d680_65ee7864336548baa944326dab545015.pdf?index=true
- https://cdn-cms.f-static.net/uploads/4387040/normal_601128fe6c2af.pdf
- https://cdn.sqhk.co/rasepotobami/XlZiggi/16439985375.pdf
- https://cdn.sqhk.co/xawefigi/nihEaih/hockey_games_near_me_this_weekend.pdf
- https://cdn-cms.f-static.net/uploads/4419192/normal_60446ef31b3db.pdf
- https://81d89a68-18ac-4cf1-ad00-ddd5d2f7da41.filesusr.com/ugd/ed58ef_14c1cc34a8624fa085dccfe0db3bd7d4.pdf?index=true
- https://cdn-cms.f-static.net/uploads/4461773/normal_606a336dbd642.pdf
- https://0115c081-d8bc-4983-a705-81db93bf1442.filesusr.com/ugd/990402_b942fc5540264c4b8a99c82d85de321a.pdf?index=true
- https://toxobeveja.weebly.com/uploads/1/3/1/4/131437160/joxanutigij.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- dugedepap.ru
- 88966db1-4a83-4446-b941-f65022a6235f.filesusr.com
- bomaripuxizidul.weebly.com
- cdn.sqhk.co
- static.s123-cdn-static.com
- cdn-cms.f-static.net
- 459ec6dd-5b69-4322-a182-74abbfaa0e48.filesusr.com
- 70010cfe-69b1-4fe9-a336-bdfe2418dc1e.filesusr.com
- 81d89a68-18ac-4cf1-ad00-ddd5d2f7da41.filesusr.com
- 0115c081-d8bc-4983-a705-81db93bf1442.filesusr.com
- toxobeveja.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 4.150.223.113
- 52.123.252.215
- 4.230.171.124
- 74.178.76.128
- 74.178.76.54
- 20.165.94.63
- 52.123.129.14
- 40.103.64.242
- 20.184.175.2
- 203.26.79.13
- 20.184.175.20
- 52.123.252.236
- 48.192.143.121
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report