MALICIOUS — 879c9aa832f4a5d4d30770a52be5a8e2ed018a5cdedf68387a311388a3a7f7a3
MALICIOUS — 879c9aa832f4a5d4d30770a52be5a8e2ed018a5cdedf68387a311388a3a7f7a3 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
879c9aa832f4a5d4d30770a52be5a8e2ed018a5cdedf68387a311388a3a7f7a3 - SHA-1:
31c363f6155e016783b9fe3376ca9ecfdc1c267a - MD5:
59861a9f111dfeca1267fd95350bb5b7 - ssdeep:
1536:jvpQK769vZNmhzRpkzP1wxk3ql54RO+lCTuuHUneUdx4mvWOKujlCYwUPaZ4PlOG:juvZUh9sjabTuu0ne84qfcoPa6PlODmP - TLSH:
T13939CFF321DBDD4C668BDF0369FA05BDA58AD3446062EB5000C8AA7C95BC97EBF00951 - Submitted as: 879c9aa832f4a5d4d30770a52be5a8e2ed018a5cdedf68387a311388a3a7f7a3
- File type: pdf · Size: 84865 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 15 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: http://xn--q20b13r9leepaeb.net/upload/file/202110080327376785.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://adikkedua.com/contents/files/98306526404.pdf, https://maxflowfans.com/userfiles/file/72916168442.pdf, http://www.musicmaestrodiscos.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1615e20f65d749---12708440195.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9656 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787880396&P2=404&P3=2&P4=I7BqPoRYqym%2b3mx2CXWyq2h62pX9rreiePMMmR6VRvH5eu2O5A7SL1w5ZJEHUvXGoDAF2cQbb0u94rSN3rCfQg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787880410&P2=404&P3=2&P4=PIfBYiFAc06vME3yA4xwFOQ8RppVFjPVu45AZVGJkTiGVB7m4MzL8jTPjwuS19nF0k6a8%2b1E8EhUDHSljOV5nA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787277107&P2=404&P3=2&P4=T54EBJN3E%2f%2bFpR6W1DgZa6g01ch8TPU%2bGy6gTaBKdyk8DLMM%2b5VeL2fdcRzC1lBNYSTZ6fOXFy68n%2fnWBaIwxQ%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
b4e1b8051b0e39ffac4875ee4f287ee795889a9829c358a206b5e7023b821942 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\7a24d505bd52985e53b6854428ac7645.png -
10944d2682e077c7f83cf84f050c313be709699106f9928320df34dfe4e5d2df - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/Gsjc/~3/BGAemAmcdTc/uplcv?utm_term=own+house+dream+quotes
- https://adikkedua.com/contents/files/98306526404.pdf
- https://maxflowfans.com/userfiles/file/72916168442.pdf
- http://www.musicmaestrodiscos.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1615e20f65d749---12708440195.pdf
- http://www.1atlanticfunding.com/wp-content/plugins/formcraft/file-upload/server/content/files/161557ea153589---73400643797.pdf
- https://newsru.md/upload/userfiles/files/16781594411.pdf
- https://realimpacto.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16162884486efa---2698914375.pdf
- https://villadelauca.com/userfiles/file/29071331800.pdf
- http://xn--q20b13r9leepaeb.net/upload/file/202110080327376785.pdf
- https://study-go.info/wp-content/plugins/super-forms/uploads/php/files/03f25562970f96984018758113ee5cb1/90994134236.pdf
- http://aviatechinform.ru/sadm_files/78135420374.pdf
- http://universalthailand.com/images/uploads/ckfinder/files/15018130631.pdf
- http://ohadalegistrocbarter.com/ckeditor/uploads/files/jipurenebupulus.pdf
- https://immobiliareincentro.it/allegati/file/16256394311.pdf
- https://svltv.in/userfiles/files/50902150818.pdf
- http://digivideos.net/ckfinder/userfiles/files/24425281396.pdf
- https://playindiano1.in/ckfinder/userfiles/files/terugeluxamefalitiwa.pdf
- http://tt-ural.su/admin/ckfinder/userfiles/files/10482533880.pdf
- https://travelselection.us/wp-content/plugins/formcraft/file-upload/server/content/files/1614ef2204c9fa---73771911867.pdf
- http://www.canadiantreasurer.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614ee6bf16127---pewumufar.pdf
- http://apcmagon.com/userfiles/52108441635.pdf
- http://samarthservice.com/userfiles/file/nutuxuxabebapogivewisowe.pdf
- http://gardena.crazyrockinsushi.com/uploads/files/dinez.pdf
- http://hellnocancershow.com/wp-content/plugins/formcraft/file-upload/server/content/files/1615f90aebff53---kowufewanumowikolad.pdf
- http://inoxbienhoa.com/upload/files/51382681295.pdf
Embedded domains
- feedproxy.google.com
- adikkedua.com
- maxflowfans.com
- www.musicmaestrodiscos.co.uk
- www.1atlanticfunding.com
- realimpacto.com.br
- villadelauca.com
- xn--q20b13r9leepaeb.net
- study-go.info
- aviatechinform.ru
- universalthailand.com
- ohadalegistrocbarter.com
- immobiliareincentro.it
- svltv.in
- digivideos.net
- playindiano1.in
- tt-ural.su
- travelselection.us
- www.canadiantreasurer.com
- apcmagon.com
- samarthservice.com
- gardena.crazyrockinsushi.com
- hellnocancershow.com
- inoxbienhoa.com
- sakurahoaanhdao.com
Embedded IP addresses
- 52.123.252.229
- 4.230.171.124
- 52.230.59.222
- 74.178.76.128
- 4.150.223.107
- 20.112.250.133
- 52.123.128.14
- 52.168.112.66
- 20.184.175.12
- 72.145.35.102
- 203.26.79.13
- 92.223.78.30
- 48.192.143.121
- 4.150.223.108
- 20.184.175.13
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report