MALICIOUS — 87d11281d6abc22b668792f48e7aa9e541cd35cef23e61de98d2b8cd4d19157f
MALICIOUS — 87d11281d6abc22b668792f48e7aa9e541cd35cef23e61de98d2b8cd4d19157f is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
87d11281d6abc22b668792f48e7aa9e541cd35cef23e61de98d2b8cd4d19157f - SHA-1:
41faac50dbb0dd909176b8fa22b68bfe6b2e717f - MD5:
6c78d2f6a5fa42caeaf8d575f6fff592 - ssdeep:
1536:a01G/nyL/pXCodcXasqLsoUvmWLSgAevFF7badPRRz84Kt8cBQFB+jNFcwE8RZJE:JofU/hZKKRLMLSDiF5Uj8jjBm+gwE8Pu - TLSH:
T1A738D0F36157DD9C6AE9EB037AE3102D78C2D7986031DE9148883B2CC8BC6BD6D14A51 - Submitted as: 87d11281d6abc22b668792f48e7aa9e541cd35cef23e61de98d2b8cd4d19157f
- File type: pdf · Size: 82065 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!6C78D2F6A5FA
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 15 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://0f285ee0-1b14-49a2-8a3e-060a2db94812.filesusr.com/ugd/4bf67f_7aa6bd02d25c462788255f8f2acafd05.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://maypoin.ru/strik?utm_term=restaurant+franchise+operations+manual+example, https://cdn.sqhk.co/kixituvelil/sxieahh/senivunadedibuleme.pdf, https://jevokave.weebly.com/uploads/1/3/4/2/134266272/5035019.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (11 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9922 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787838962&P2=404&P3=2&P4=jW%2fXIqWcMv%2fb8MkhzdsYYNtS3mmuUbtetV7HX5uaMoR5uexGeOpQKWTaQNqqCt7A814Kuqzdg27JvE7qbn3eEA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787839017&P2=404&P3=2&P4=X9d5cytNSneBw7mOu9Zag7cdSECWltuLLkD0dXBzZJ9ooMCUwWpdsfJZY8LuZwAtVeS1u74OZPlp%2bi5Wha07zA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787235717&P2=404&P3=2&P4=jiv18QhgUw98HS2M3fG%2fohgsDJxjxS3Fu2Nem4dNTTg5nkqgbS37wlyJNu1EXHfHlbi7L8L3bIuTnUcb0l7zCw%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
71e0fb0ab64d373ee8f8f4baf4b52dddd3d681256d94034def10a9ea07b2d638 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\81f449f775562e21eb0b54cad8d5b875.png -
6aaf98aa594dc10da749537e0bddc79da06cdd6e6a157b34dd0410bd6f2e5ef9 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://maypoin.ru/strik?utm_term=restaurant+franchise+operations+manual+example
- https://cdn.sqhk.co/kixituvelil/sxieahh/senivunadedibuleme.pdf
- https://s3.amazonaws.com/towakog/93396803781.pdf
- https://jevokave.weebly.com/uploads/1/3/4/2/134266272/5035019.pdf
- https://bigonokefexix.weebly.com/uploads/1/3/4/5/134518339/legaparuk-gorelop-jomivomaradezi.pdf
- https://cdn.sqhk.co/xadakede/7L7jc9W/18459226862.pdf
- https://jojiwunu.weebly.com/uploads/1/3/5/3/135387754/fululowetuxi_pejiw.pdf
- https://zunutupere.weebly.com/uploads/1/3/1/4/131453944/606fbc.pdf
- https://vizisovi.weebly.com/uploads/1/3/4/1/134131984/288919.pdf
- https://0f285ee0-1b14-49a2-8a3e-060a2db94812.filesusr.com/ugd/4bf67f_7aa6bd02d25c462788255f8f2acafd05.pdf?index=true
- https://4a31e3f8-49e3-4331-b1a9-c0bb7a6b9dbc.filesusr.com/ugd/599f1c_58aa01d4bc564b85bbd54f65608170e2.pdf?index=true
- https://cdn.sqhk.co/dijowasedop/l0J5jfO/lesofa.pdf
- http://lazerepil.site/289546104503ycpp.pdf
- https://zikixitifo.weebly.com/uploads/1/3/4/8/134897390/7041744.pdf
- https://cdn.sqhk.co/xomakonezema/gdig51U/baresusazarilapo.pdf
- http://iciapp.xyz/rixijuzosaxatibamk1yv.pdf
- https://sirabirimafo.weebly.com/uploads/1/3/0/7/130739431/fabedoridaker.pdf
- https://cdn.sqhk.co/titolegun/ohe4hgg/mikefuvujaruful.pdf
- https://a161ff94-1a6f-4367-b6f8-8e513a5e676d.filesusr.com/ugd/4c7633_66069fb333fb41fdaecf42beb4d16748.pdf?index=true
- https://s3.amazonaws.com/lurutopobi/xubefimonasixidiroj.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- maypoin.ru
- cdn.sqhk.co
- s3.amazonaws.com
- jevokave.weebly.com
- bigonokefexix.weebly.com
- jojiwunu.weebly.com
- zunutupere.weebly.com
- vizisovi.weebly.com
- 0f285ee0-1b14-49a2-8a3e-060a2db94812.filesusr.com
- 4a31e3f8-49e3-4331-b1a9-c0bb7a6b9dbc.filesusr.com
- lazerepil.site
- zikixitifo.weebly.com
- iciapp.xyz
- sirabirimafo.weebly.com
- a161ff94-1a6f-4367-b6f8-8e513a5e676d.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.110.12.33
- 4.230.171.124
- 4.144.132.223
- 135.233.95.144
- 20.165.94.54
- 20.76.201.171
- 74.178.76.44
- 52.123.128.14
- 52.123.129.14
- 40.99.134.18
- 203.26.79.13
- 52.123.252.248
- 92.223.78.30
- 52.182.143.212
- 20.184.175.6
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report