MALICIOUS — 73648429706.pdf
MALICIOUS — 73648429706.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
87cb7bbb810e583ca15fae176f9bd8271056aeb1db93920444d4d1f2a44c90f8 - SHA-1:
f1939c3b3d9cdec02b985d4a904b29f62c804f2b - MD5:
55d2c301b1f4a7a45394c2bada6b2a9e - ssdeep:
1536:0lMAnYRiEvPVlKrxG3UV1K9wGlGd5lYKF/9xWY2chWkESGRrxaNCOHWUpO7HIWDb:pAnYwE3Vgr6wGlm5/VvWY2xRrxaNCO6h - TLSH:
T1C038B0E32097DE9C7ACB9F8778EA419CA48B87847171D69040C8B76C94BC4BE7F04A51 - Submitted as: 73648429706.pdf
- File type: pdf · Size: 82021 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 13 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/160aff698bb806---wunasanulorilobego.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://pistant.ru/uplcv?utm_term=siemens+sitrans+probe+lu+manual+espa%C3%B1ol, https://lawina-radom.pl/files/file/xuxajifizerekojag.pdf, http://amwordpress.org/wp-content/plugins/formcraft/file-upload/server/content/files/160aa52bba51c6---maduzexutezoxixibasenaj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9741 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- _dosvc._tcp.local
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\19a32870b860e6fbffda67b7759e8f51.png -
f37ff7f3017e1218f94bd8587e35a6884c0b32606db87b08b5c4ee9548dcc3e7 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
5d39df65c824ad0f19817f4a31ce60be413b71e2f0043cd7e6b701bd97759016 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://pistant.ru/uplcv?utm_term=siemens+sitrans+probe+lu+manual+espa%C3%B1ol
- https://lawina-radom.pl/files/file/xuxajifizerekojag.pdf
- http://amwordpress.org/wp-content/plugins/formcraft/file-upload/server/content/files/160aa52bba51c6---maduzexutezoxixibasenaj.pdf
- https://freedomhypnosisnyc.com/wp-content/plugins/super-forms/uploads/php/files/19c7244f45696963908e8882556beee4/24208006626.pdf
- https://ivfnna.gr/wp-content/plugins/super-forms/uploads/php/files/2d6b8a1a97dfd63fbf915e68b1b4df02/44389326048.pdf
- https://sca-eagleegg5k.com/ckfinder/triplebuserfiles/file/jorunajexoguz.pdf
- http://www.olympussverige.se/wp-content/plugins/super-forms/uploads/php/files/uors69qisq76vkk4iveiff4tdd/37002244615.pdf
- http://bright-mineral.com/uploadfile/file/2021081300140898.pdf
- http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/160aff698bb806---wunasanulorilobego.pdf
- http://www.airportlimofortlauderdale.net/wp-content/plugins/formcraft/file-upload/server/content/files/160a2bc5d19632---26180647615.pdf
- http://veronicanealhome.com/wp-content/plugins/formcraft/file-upload/server/content/files/2/160de26fc2ff1f---27439603312.pdf
- https://learn-atdi.com/uploads/files/ritutunav.pdf
- http://michalpavlicek.com/uploaded/file/lazuwilarezefujub.pdf
- http://aiswaryamatrimonials.com/fck_uploads/file/7189228817.pdf
- https://smarttactic.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1607d1f59c3bd0---75638507327.pdf
- http://dinskayarealty.ru/media/file/tukupozoxamikufemodazaf.pdf
- https://motionslam.com/wp-content/plugins/super-forms/uploads/php/files/554c0c2c97b955abc0005f9def1477c8/79205412500.pdf
- https://www.verpoort-bouw.be/wp-content/plugins/formcraft/file-upload/server/content/files/1607636561b9ae---pavatepabixaxelukunifar.pdf
- http://ophirtonhotel.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/1607941b3ee33e---45951487817.pdf
- http://jrpst.pl/userfiles/file/38033206718.pdf
- https://saftanton.dk/wp-content/plugins/formcraft/file-upload/server/content/files/16072990993b71---nanosofetumagekalopu.pdf
- http://abapaposentados.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1609306f4785a4---55281156573.pdf
- http://kgmda.com/upload/files/fufadibopanojenetu.pdf
- https://veterinarycarefoundation.org/userfiles/file/47412667569.pdf
- http://jagatjyotischool.org/jagatjyotischool/userfiles/file/35377318906.pdf
Embedded domains
- pistant.ru
- lawina-radom.pl
- amwordpress.org
- freedomhypnosisnyc.com
- sca-eagleegg5k.com
- www.olympussverige.se
- bright-mineral.com
- kaufdeinauto.de
- www.airportlimofortlauderdale.net
- veronicanealhome.com
- learn-atdi.com
- michalpavlicek.com
- aiswaryamatrimonials.com
- dinskayarealty.ru
- motionslam.com
- www.verpoort-bouw.be
- ophirtonhotel.co.za
- jrpst.pl
- abapaposentados.com.br
- kgmda.com
- veterinarycarefoundation.org
- jagatjyotischool.org
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 20.42.179.204
- 20.42.65.93
- 162.159.142.9
- 52.110.12.46
- 4.230.171.124
- 135.233.95.144
- 135.233.95.135
- 20.76.201.171
- 52.123.128.14
- 203.26.79.13
- 74.179.71.159
- 4.207.44.72
- 4.209.250.170
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report