MALICIOUS — 75f7a210a65c2861047bb789c5939c21b326bdc529dc9be954c11bfdf65b2f97
MALICIOUS — 75f7a210a65c2861047bb789c5939c21b326bdc529dc9be954c11bfdf65b2f97 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
75f7a210a65c2861047bb789c5939c21b326bdc529dc9be954c11bfdf65b2f97 - SHA-1:
e2b9f3a038aaa533c9b83e0ebaf6f0e00e26e820 - MD5:
74fecfad0098ffe6774528a187066859 - ssdeep:
1536:Oo8MZBBMDoUL5kGXsh2SMaeplRlkg2CsL3LOEk4Lasr:F8SBUoe6XbHepCgFs7LOULD - TLSH:
T18F37D1F35297ED8CB6865B03BEB6352D655DD3485232E2A0548C776CC8782FE7D10A10 - Submitted as: 75f7a210a65c2861047bb789c5939c21b326bdc529dc9be954c11bfdf65b2f97
- File type: pdf · Size: 76340 bytes
- Verdict: malicious (98/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!74FECFAD0098
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/997e903c-43ef-43cc-a8e7-6375f5abdae4/legendary_brawl_stars_apk_mod_android_1.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 14 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://krisoc.ru/pbw?utm_term=how+to+hack+8+pool+coins+and+cash, https://siputewebototab.weebly.com/uploads/1/3/4/4/134480832/zonulufif.pdf, http://kedefoviraj.pbworks.com/f/sports_certificate_template_word_free_download.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9684 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787813181&P2=404&P3=2&P4=HOiV1l5vUAFX%2fQlC26tr26qgcVNZV%2f%2fvNVS7JiBJVKyK%2f1KFblaKYVD9PFlpBhRz0%2f9mLoQUaeRScutWvkdQDw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787813249&P2=404&P3=2&P4=cgmjwxF%2bC3B%2fiFh42DXU6EZlg0dat%2f3QpUr56VcCfa3Ud19SSS%2b17VtRMzrxOT5O%2bUIKc8tV9FUfcQqS69yRmw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- 23.40.52.209
- 23.11.37.157
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
0c533d9dd5f9af5a375ba1bb8bb35b8ba5cbc6346a14f61c85f8a52898bc6703 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\912f68cb04a91605a72d3754d0b54614.png -
8b8a6e188e67657a5b00e23fe59f2073719bd81b008c759d4d5f6af7d05e928e - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://krisoc.ru/pbw?utm_term=how+to+hack+8+pool+coins+and+cash
- https://siputewebototab.weebly.com/uploads/1/3/4/4/134480832/zonulufif.pdf
- http://kedefoviraj.pbworks.com/f/sports_certificate_template_word_free_download.pdf
- http://mawasuwov.pbworks.com/f/famajozo.pdf
- http://puzavofan.pbworks.com/w/file/fetch/144578892/84768317566.pdf
- https://uploads.strikinglycdn.com/files/997e903c-43ef-43cc-a8e7-6375f5abdae4/legendary_brawl_stars_apk_mod_android_1.pdf
- http://vixifalino.pbworks.com/w/file/fetch/144573786/xenuvojarixodigijadazalob.pdf
- https://cdn-cms.f-static.net/uploads/4421614/normal_604ae8a775100.pdf
- https://cdn-cms.f-static.net/uploads/4486965/normal_5fe9d3956a611.pdf
- http://sovafiben.pbworks.com/w/file/fetch/144543324/24680124735.pdf
- https://cdn-cms.f-static.net/uploads/4374372/normal_602b2ada10e78.pdf
- https://uploads.strikinglycdn.com/files/14451ed6-8eb5-4c85-989b-241f95ac7395/11102952290.pdf
- http://dekokos.pbworks.com/f/13610793161.pdf
- https://lerorenoj.weebly.com/uploads/1/3/5/3/135390996/niladajira_namelubafemes_zixadiwu.pdf
- http://fufitiruw.pbworks.com/w/file/fetch/144568617/42784283369.pdf
- http://sagidetubi.pbworks.com/w/file/fetch/144550839/zowedurixitavasofebum.pdf
- https://cdn-cms.f-static.net/uploads/4369174/normal_60661e1306a30.pdf
- http://fokopaviwu.pbworks.com/f/dicionario_portugues_ingles_baixar.pdf
- https://uploads.strikinglycdn.com/files/1df9abab-e92b-40bf-be0a-46c6bca7e9d7/spark_book_dragon.pdf
- http://wemilamozede.pbworks.com/w/file/fetch/144550989/53735223207.pdf
- http://xesimisejek.pbworks.com/f/69995585826.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- krisoc.ru
- siputewebototab.weebly.com
- kedefoviraj.pbworks.com
- mawasuwov.pbworks.com
- puzavofan.pbworks.com
- uploads.strikinglycdn.com
- vixifalino.pbworks.com
- cdn-cms.f-static.net
- sovafiben.pbworks.com
- dekokos.pbworks.com
- lerorenoj.weebly.com
- fufitiruw.pbworks.com
- sagidetubi.pbworks.com
- fokopaviwu.pbworks.com
- wemilamozede.pbworks.com
- xesimisejek.pbworks.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.182.143.212
- 125.56.205.51
- 52.110.12.50
- 52.110.12.37
- 4.230.171.124
- 125.56.205.8
- 4.150.223.103
- 20.231.239.246
- 135.232.92.137
- 52.123.128.14
- 135.234.160.245
- 20.165.94.46
- 203.26.79.13
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report