MALICIOUS — 88ad0fe191017293367dc2f75acc714225657f1ed57373a2b121a4dd21c0f831
MALICIOUS — 88ad0fe191017293367dc2f75acc714225657f1ed57373a2b121a4dd21c0f831 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
88ad0fe191017293367dc2f75acc714225657f1ed57373a2b121a4dd21c0f831 - SHA-1:
579640cc6c284d1cf2d7ed6b591b83c90971fa1c - MD5:
4d8c75d3448069af6ec556ecbbb9dc9a - ssdeep:
1536:KdwbI8kZBxmQgGBkBoQY0gVTo86duWOpOwrKWwdscI/CcBV1:PI8CBEhJoQxLDwrETmNx - TLSH:
T18A37CFF312A3DD4C7A93CB4369AB12ACA14AD7596263EB502088B77CC97C5BDBF10510 - Submitted as: 88ad0fe191017293367dc2f75acc714225657f1ed57373a2b121a4dd21c0f831
- File type: pdf · Size: 71745 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://preciseenergygroup.com/media/lomotewukot.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 16 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://curry-box-deluxe.de/userfiles/file/bipalanafulibenanufojulo.pdf, https://www.colegiumaniucarei.ro/ckfinder/userfiles/files/470782926.pdf, http://cosmikkino.ru/sadm_files/95777698653.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9705 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787899264&P2=404&P3=2&P4=Vzl5egYIYxWqbXZ%2fNeKoBjFGJ1FRClBOXzlD7z6ohdUU25ePSMpuy%2frHf1cR2IoLagoJJtYN2UuWiVoS%2bMQ0HQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
faaa5f3a82d2f8613afd9b1763540b92dbd8faa31db5195d9f7988a8c0ffc72c - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\2bd754fd7815db254fecfcba05ab8857.png -
19d8c1183269dfdd02292fe9cb699161e7be7b22d7c7533c9ac1cac1b75b275f - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/PmAiG5ZyT-k/uplcv?utm_term=most+word+processing+software+can+be+used+for+which+3+of+the+following+tasks
- http://curry-box-deluxe.de/userfiles/file/bipalanafulibenanufojulo.pdf
- https://www.colegiumaniucarei.ro/ckfinder/userfiles/files/470782926.pdf
- http://cosmikkino.ru/sadm_files/95777698653.pdf
- http://infiniti.e-library.tw/uploads/files/84543188189.pdf
- https://preciseenergygroup.com/media/lomotewukot.pdf
- https://sangolongphuong.vn/longphuong/news/files/47831939464.pdf
- http://zdrowejaja.com/Upload/file/91213669021.pdf
- http://tangneylaw.com/admin/images/file/xaxuriw.pdf
- https://hobbypet.cz/files/file/ginepifatimokikozakovezel.pdf
- http://voyagevietnamlaos.com/hinhanh/file/vedam.pdf
- https://mygamedaysports.com/wp-content/plugins/super-forms/uploads/php/files/fa5e49959b69b6c617fa5b5520291f63/6825032647.pdf
- https://brokenspoke.com/wp-content/plugins/super-forms/uploads/php/files/38a4692676b80cf1d3fc978ba698517c/furakijawikimiziwaleg.pdf
- http://4grd.com/cmsimages/file/9961520514.pdf
- http://finalbrand.cz/upload/file/pupedozokoxasapivagosi.pdf
- http://wami.cc/data/files/lowijukalijuralovo.pdf
- https://octvads.site/js/ckfinder/userfiles/files/judodumiditevemunilumipi.pdf
- http://accapierre.it/userfiles/files/20787654561.pdf
- http://chengzechem.com/upload/files/66253978214.pdf
- http://phutungvespaco.com/luutru/files/39107461374.pdf
- https://purefeeling8.com/data/file/55780456617.pdf
- http://hiace-yoshikawa.com/js/upload/files/11247705427.pdf
- http://e-hematologica.pl/users/file/kebifezurefetitikutujovev.pdf
- http://stroyindustry.com/userfiles/file/julirawalutojuze.pdf
- http://cobe-ing.it/userfiles/files/jizepolubimud.pdf
Embedded domains
- feedproxy.google.com
- curry-box-deluxe.de
- cosmikkino.ru
- infiniti.e-library.tw
- preciseenergygroup.com
- zdrowejaja.com
- tangneylaw.com
- voyagevietnamlaos.com
- mygamedaysports.com
- brokenspoke.com
- 4grd.com
- wami.cc
- octvads.site
- accapierre.it
- chengzechem.com
- phutungvespaco.com
- purefeeling8.com
- hiace-yoshikawa.com
- e-hematologica.pl
- stroyindustry.com
- cobe-ing.it
- www.w3.org
- purl.org
- ns.adobe.com
- www.colegiumaniucarei.ro
Embedded IP addresses
- 162.159.142.9
- 52.230.60.54
- 52.110.12.8
- 172.215.188.225
- 4.230.171.124
- 20.184.175.2
- 135.233.95.144
- 52.123.128.14
- 40.103.64.242
- 72.145.35.97
- 203.26.79.13
- 20.42.65.88
- 92.223.78.30
- 135.233.45.222
- 172.170.180.133
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report