MALICIOUS — 85af19c06380dad59ae6120377b175140142d58a0eea443ff0c89a662d28ec22
MALICIOUS — 85af19c06380dad59ae6120377b175140142d58a0eea443ff0c89a662d28ec22 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
85af19c06380dad59ae6120377b175140142d58a0eea443ff0c89a662d28ec22 - SHA-1:
02e6b05f8f4b74c7af229f1c8292d57bcdbba56e - MD5:
1796b57c5cd94886fc187ea6e14f4b0c - ssdeep:
1536:niAd0cmLPbDNL0BjgGYYXGlAw8cSLidc++TcWXamX21GcW6pOu2kkLqNd:7d0cmLzR0NgGYMyMRLNlT1XgGVu2ksw - TLSH:
T10937BFF3518BDCCC7B829F036AAB019DE58ED7881191E690448CB73CE57CABDBA14650 - Submitted as: 85af19c06380dad59ae6120377b175140142d58a0eea443ff0c89a662d28ec22
- File type: pdf · Size: 71417 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://conditum.nl/userfiles/file/39934627281.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 19 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://infrive.ru/uplcv?utm_term=anger+stick+mod+apk, https://goodnest.info/tctt/sites/aaa/file/2428462265.pdf, http://tl-maskinfabrik.dk/userfiles/file/zukule.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9584 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 78.0.240.10.in-addr.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787829061&P2=404&P3=2&P4=gVDxObkLbiIqlOPrFF5EDdzXtmKAP2zb4zQSP6cwHVpdSp2z%2bf4msfIZz8mKHghYdxceR5rKo5jLmvAXmxDySA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787829091&P2=404&P3=2&P4=eHxsJmLH4f0r1LJHc8393G1ZTPtZSk6fSCMPX%2f6xHkNMHk8ZQHiCTMhiizSfcRKFSnNq58TpBZmGCCrJpH6N5g%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\69d96ca8c9f8f59c6c5564dcf71aec68.png -
cbecb1b80a693cefaef609197775f01d6a633b12932f40d80b87e0358a4cc3cc - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
4b4d8c5f72d6d823634a5ec4c514d0289a1bf863b2eb926ab917e00c8e78cd6a - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://infrive.ru/uplcv?utm_term=anger+stick+mod+apk
- https://goodnest.info/tctt/sites/aaa/file/2428462265.pdf
- http://tl-maskinfabrik.dk/userfiles/file/zukule.pdf
- http://songpinhao.com/userfiles/files/bejif.pdf
- https://youxsoft.com/uploads/files/novenoniwalofumebunoni.pdf
- https://hilanguage-com-tw.triangle-design.com/files/2703566556.pdf
- https://stormester.no/files/file/22083438149.pdf
- http://wingmanresearch.com/userfiles/files/2033649440.pdf
- http://stefanourso.com/public/userfiles/file/13432248680.pdf
- http://conditum.nl/userfiles/file/39934627281.pdf
- http://soupworld.de/upload/file/24971525164.pdf
- http://imosa.asia/uploads/files/202109010804333069.pdf
- http://vansuloi.com/uploads/userfiles/file/nojorekujedafeserezis.pdf
- http://vimar.ua/userfiles/files/78132779980.pdf
- https://fullmagicweekend.com/ckfinder/userfiles/files/vizagafosavugawawexapid.pdf
- https://www.baileysmilk.com/wp-content/plugins/super-forms/uploads/php/files/43a4570f5986e52e82a0eb344bc065cb/mozosokasopivakezoxikuzur.pdf
- https://iphone-odklep.si/vsebina/vumetefaparisugozizosok.pdf
- https://mbzgogo.xyz/web/img/podborky/files/59576940999.pdf
- http://erkerlaender.de/wp-content/plugins/formcraft/file-upload/server/content/files/1614ef73245532---62039057978.pdf
- https://bokaichenyu.com/upload/files/88843692313.pdf
- http://szjwwj.com/userfiles/file///18640354023.pdf
- https://habibitours.org/ckfinder/userfiles/files/5348396717.pdf
- https://www.18fire.com/wp-content/plugins/super-forms/uploads/php/files/738e1b5795b3dd37b29d3b3043e27f65/77235463987.pdf
- http://smart.sut.ac.th/tsme/src/lib/ckfinder/userfiles/files/vijupuvuvisesagudefid.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- infrive.ru
- goodnest.info
- songpinhao.com
- youxsoft.com
- hilanguage-com-tw.triangle-design.com
- stormester.no
- wingmanresearch.com
- stefanourso.com
- conditum.nl
- soupworld.de
- imosa.asia
- vansuloi.com
- vimar.ua
- fullmagicweekend.com
- www.baileysmilk.com
- mbzgogo.xyz
- erkerlaender.de
- bokaichenyu.com
- szjwwj.com
- habibitours.org
- www.18fire.com
- www.w3.org
- purl.org
- ns.adobe.com
- tl-maskinfabrik.dk
Embedded IP addresses
- 20.184.175.5
- 4.150.223.110
- 92.223.78.30
- 52.123.252.240
- 40.84.97.4
- 4.230.171.124
- 85.210.196.11
- 52.230.59.222
- 135.232.92.137
- 74.178.76.54
- 20.231.239.246
- 40.99.133.210
- 52.123.128.14
- 13.89.179.15
- 52.123.252.219
- 72.145.35.96
- 203.26.79.13
- 48.199.12.1
- 52.168.117.169
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report