MALICIOUS — 54608552682.pdf
MALICIOUS — 54608552682.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
7d9b2b8dcc94df06a237d3d0757769c55cdf367746b0041aa02e6fb93d777a21 - SHA-1:
eecb8717bf69cdde6048633f7e7c7cdfdc6161ff - MD5:
bade98e658c8320f5a0328b01adad39e - ssdeep:
1536:LC0iUx/rYlE61mcB5EilpKjknnk15kofcZ9ia1SBWpT5jFY0nu1EIpGuWBkMff:W07xT4zRfEilEjknkrgwBKVjFY0nuyIY - TLSH:
T1BF38CFF37197EC8CA98B7B87E897554A6447D38B3522E6B0148877ACC07C2ED7E10921 - Submitted as: 54608552682.pdf
- File type: pdf · Size: 78856 bytes
- Verdict: malicious (99/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!BADE98E658C8
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4385206/normal_5fc9818070f94.pdf - network signal, weight 0.70, confidence 0.80
- Memory forensics: 3 finding(s), e.g. RWX/private injected region in SumatraPDF.exe (pid 8992) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Contacted 16 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://baarspo.ru/strik?utm_term=sig+sauer+p226+vs+legion, https://gilepijojuju.weebly.com/uploads/1/3/2/7/132740412/nudati_bobavipujozo.pdf, http://jimugen.epizy.com/hansel_and_gretel_cast_2020.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (13 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9615 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- c.pki.goog
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787773281&P2=404&P3=2&P4=m5157w0BkSVdJXIoz%2b0WOfWzsXXEEfCaetdemWUmu%2fr%2f7YphskOlMz%2bBsewiIfgsy8EHOQ2%2bnqGoLa9F6JoJ9A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
4f24f46e71cdd3d45d4b5b5e6492dd65e799583e7010ab41f4d77b64e48f583d - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\4680e1b16d5e7e70f96c6a6e726e664f.png -
76c5cf442fa647aec68937b073f791a31b2f1886a7e9f58b768663054a676809 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://baarspo.ru/strik?utm_term=sig+sauer+p226+vs+legion
- https://gilepijojuju.weebly.com/uploads/1/3/2/7/132740412/nudati_bobavipujozo.pdf
- http://jimugen.epizy.com/hansel_and_gretel_cast_2020.pdf
- http://sutexuvidag.myartsonline.com/how_long_to_read_the_handmaids_tale.pdf
- http://tafiwepamubov.atwebpages.com/merit_badge_university_2020_missouri.pdf
- http://lobakixadob.epizy.com/canada_immigration_application.pdf
- https://static.s123-cdn-static.com/uploads/4385206/normal_5fc9818070f94.pdf
- https://kiniwotonupit.weebly.com/uploads/1/3/0/7/130776343/zivetiponizaje.pdf
- https://cdn.sqhk.co/wemopizajazo/2jbCRji/57055815384.pdf
- https://s3.amazonaws.com/pizivurapab/yowhatsapp_version_8.pdf
- http://fuvarijes.atwebpages.com/how_to_replace_panasonic_microwave_bulb.pdf
- http://rutefozur.22web.org/facebook_bot_developer_guide.pdf
- https://cdn-cms.f-static.net/uploads/4408172/normal_6035454b8f4ab.pdf
- https://s3.amazonaws.com/mexavofezoxi/jilagoforamejelekerarugor.pdf
- https://static.s123-cdn-static.com/uploads/4375716/normal_5fe16dc53d23e.pdf
- https://s3.amazonaws.com/fokapikow/nanuxupiraw.pdf
- https://sakenudawajaka.weebly.com/uploads/1/3/4/5/134595508/5625414.pdf
- https://wobufijurix.weebly.com/uploads/1/3/1/6/131607063/zuwepolutomofu_zebefejuv.pdf
- http://kepibarufot.22web.org/54901065557.pdf
- http://nageramuvepom.mywebcommunity.org/tripura_rahasya_hindi.pdf
- https://s3.amazonaws.com/joterige/autodock_4_manual.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- baarspo.ru
- gilepijojuju.weebly.com
- jimugen.epizy.com
- sutexuvidag.myartsonline.com
- tafiwepamubov.atwebpages.com
- lobakixadob.epizy.com
- static.s123-cdn-static.com
- kiniwotonupit.weebly.com
- cdn.sqhk.co
- s3.amazonaws.com
- fuvarijes.atwebpages.com
- rutefozur.22web.org
- cdn-cms.f-static.net
- sakenudawajaka.weebly.com
- wobufijurix.weebly.com
- kepibarufot.22web.org
- nageramuvepom.mywebcommunity.org
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 57.154.63.210
- 4.150.223.112
- 20.247.185.124
- 72.154.7.96
- 203.26.79.13
- 4.230.171.124
- 135.233.95.135
- 20.165.94.63
- 40.99.133.226
- 52.123.128.14
- 40.104.4.2
- 52.123.252.244
- 57.155.104.224
- 142.250.195.163
- 20.184.175.2
- 4.209.250.170
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report