MALICIOUS — vobupesifod.pdf
MALICIOUS — vobupesifod.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7fda84e2da1592928c103945e4f302c3a391bf77ebd75ef4f4119c49aa49a599 - SHA-1:
7c74bdc963fa78d680ec1d97260b52ba1d2dc900 - MD5:
85fcf11d9cec2c90490d42703752cecc - ssdeep:
1536:4Rmhu2yCApSIGEOmHO3MHFGjxPjFWrcN0BcIWxkc7XW2jhP6JrWQpOCoWmQbvMPJ:PhJyCADGEOmFGlYrViImPmUhSJWCHbER - TLSH:
T14039C0F3205BED0C7A4B4F53AAEF117CA186D78811629AA0458CF56C94FC6BD6F04A81 - Submitted as: vobupesifod.pdf
- File type: pdf · Size: 88021 bytes
- Verdict: malicious (95/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 17 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://cradlegold.com/wp-content/plugins/super-forms/uploads/php/files/cgt6c2v3bphf3uv59dmihm279j/93089922204.pdf, http://www.fsnn.se/wp-content/plugins/formcraft/file-upload/server/content/files/160abb4e844cf3---numoradaxur.pdf, https://nusantarabet4d1.com/contents/files/82013012686.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9681 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- ntp.ubuntu.com
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- _dosvc._tcp.local
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\9b4b6af822f2a6b655d48bfda0485933.png -
15e34c87ec1d1f6d7871a5170ee0e2c53306f7fcd7f48672eeac1866f1095a13 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
eb1b18ec56a0085b15e6b4e137b2abd2cfbfbd7d682f10440337fa07efba7778 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/fzgW7-mxBc0/uplcv?utm_term=fanatec+clubsport+handbrake+manual
- https://cradlegold.com/wp-content/plugins/super-forms/uploads/php/files/cgt6c2v3bphf3uv59dmihm279j/93089922204.pdf
- http://www.fsnn.se/wp-content/plugins/formcraft/file-upload/server/content/files/160abb4e844cf3---numoradaxur.pdf
- https://nusantarabet4d1.com/contents/files/82013012686.pdf
- https://actor-conseil.com/files/file/90462414322.pdf
- https://wacee.net/wp-content/plugins/formcraft/file-upload/server/content/files/16090465ec2a8b---fetududutamoj.pdf
- https://ahi.com.ua/wp-content/plugins/super-forms/uploads/php/files/731d250c32d9c2fba048089c63f214b8/zenogigegis.pdf
- https://myshalewell.com/userfiles/file/duligezafonadem.pdf
- https://www.penyembuhanholistikreiki.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f2b81899cc---janowunoxixenet.pdf
- http://uzmansporzeminkaplama.com/resimler/files/25872358923.pdf
- https://aldea.work/wp-content/plugins/super-forms/uploads/php/files/dce9e26c7fe397831cf6fad2a8e8f212/37415651310.pdf
- http://taxfreepoint.com/file/nexagato.pdf
- https://leo-translate.com.ua/wp-content/plugins/formcraft/file-upload/server/content/files/160753917115d8---74056880731.pdf
- https://yarsan.ru/wp-content/plugins/super-forms/uploads/php/files/c6af1e90eec00571d62d7e76aa3a3a49/93825242597.pdf
- https://livingcircles.ch/wp-content/plugins/formcraft/file-upload/server/content/files/160ab7bc95e868---61830534209.pdf
- http://holidayservicemarsala.it/userfiles/files/mobitoberirosolefaxizoto.pdf
- http://nd-58.ru/wp-content/plugins/super-forms/uploads/php/files/e6de971dbd1e878b7369dd50794fa6eb/9275900925.pdf
- https://g-ortho.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160d63e8de4a2f---vasobunulelisukitimadiw.pdf
- http://cukierniabrzezinski.pl/www/artizam/fck/file/wowaxer.pdf
- https://puertoestereo.com/wp-content/plugins/super-forms/uploads/php/files/ppipab4n64rb91qto5lguqp7mm/36774093567.pdf
- http://www.191seo.com/wp-content/plugins/formcraft/file-upload/server/content/files/16089224536f65---bipupovaxuxopunig.pdf
- https://pbchistoryonline.org/uploads/file/wibitexagogogus.pdf
- https://vvpta-irvine.org/userfiles/file/17317600925.pdf
- https://wacee.net/wp-content/plugins/formcraft/file-upload/server/content/files/1608a1be4f2fee---tudazogakow.pdf
- http://xn--o39a91gvwm83kbsn.net/FileData/ckfinder/files/20210820_2B2B2F6AB1FBA68F.pdf
Embedded domains
- feedproxy.google.com
- cradlegold.com
- www.fsnn.se
- nusantarabet4d1.com
- actor-conseil.com
- wacee.net
- ahi.com.ua
- myshalewell.com
- www.penyembuhanholistikreiki.com
- uzmansporzeminkaplama.com
- aldea.work
- taxfreepoint.com
- leo-translate.com.ua
- yarsan.ru
- livingcircles.ch
- holidayservicemarsala.it
- nd-58.ru
- g-ortho.com.br
- cukierniabrzezinski.pl
- puertoestereo.com
- www.191seo.com
- pbchistoryonline.org
- vvpta-irvine.org
- xn--o39a91gvwm83kbsn.net
- www.w3.org
Embedded IP addresses
- 20.184.175.11
- 52.110.12.11
- 4.144.132.114
- 4.230.171.124
- 20.42.72.131
- 74.179.77.164
- 74.179.77.204
- 20.165.94.46
- 52.123.129.14
- 40.99.133.242
- 203.26.79.13
- 20.184.175.4
- 172.178.240.161
- 4.209.250.170
- 40.79.150.123
- 142.250.195.131
- 74.178.76.44
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report