MALICIOUS — 8a3680223d33d3cf015da08f9a6438cf9d2bfc66ad85d11d074b0cee5e3cf92e
MALICIOUS — 8a3680223d33d3cf015da08f9a6438cf9d2bfc66ad85d11d074b0cee5e3cf92e is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
8a3680223d33d3cf015da08f9a6438cf9d2bfc66ad85d11d074b0cee5e3cf92e - SHA-1:
ceb3fa801900afc219efa3c565ea4bcfa217eacb - MD5:
ab102c84fd78634d86c2f5e272c88d12 - ssdeep:
1536:Iirx5vnQhtZXVexdjQIk4iZvojVmoQ2sRHA53qHlojJGgK+VHIH5IQVlsloJ:eexdjQIbi60oQ2YloVGg1IHBVP - TLSH:
T18337CFF32193DE4C7A8BAB8769FB667D6449C7846161836000D8BA1CC8BC2FD6F15C61 - Submitted as: 8a3680223d33d3cf015da08f9a6438cf9d2bfc66ad85d11d074b0cee5e3cf92e
- File type: pdf · Size: 74661 bytes
- Verdict: malicious (98/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!AB102C84FD78
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4446789/normal_5ffe9ebc92ff6.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 13 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://synerhu.ru/pbw?utm_term=mathematical+methods+for+physicists+mary+l+boas+pdf, https://wekupadafar.weebly.com/uploads/1/3/5/3/135315244/9688664.pdf, https://cdn-cms.f-static.net/uploads/4372753/normal_60bedc29b234d.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (14 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9655 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787799054&P2=404&P3=2&P4=OPUtOVV04dUx519D9AK0Rg3yuh5ZfoSdEv6uyyjYhd2hvYni9OSwJTRNhJmN07JmkYAbjerenI%2fTfINwOyHVNA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787799126&P2=404&P3=2&P4=XpQ6fDJTMDk%2f2wsgMyTJCaqJdJIsQFOeQhAv07eSHq8nhQZ8oRrFoAJFhn8ZZHU97z5SfGPgy1phzM7dwxi90g%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- 23.40.52.209
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
5da6883ebee1c1c1a632bc61d5c2af7209030c7ced6d1840ed88ccf2825d9669 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\a7b745816e52e656eeda7f60ba3080b0.png -
89f31d73c1a7bfa074f17d25425c39f3f708139efa4bc5ca6340699142c9d85b - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://synerhu.ru/pbw?utm_term=mathematical+methods+for+physicists+mary+l+boas+pdf
- https://wekupadafar.weebly.com/uploads/1/3/5/3/135315244/9688664.pdf
- https://cdn-cms.f-static.net/uploads/4372753/normal_60bedc29b234d.pdf
- https://cdn-cms.f-static.net/uploads/4463810/normal_60640db06b16a.pdf
- https://static.s123-cdn-static.com/uploads/4446789/normal_5ffe9ebc92ff6.pdf
- https://ridakikasidom.weebly.com/uploads/1/3/0/7/130739592/b6d8279968f.pdf
- http://sokulus.pbworks.com/w/file/fetch/144479718/75023460347.pdf
- http://lexibitite.pbworks.com/f/80024503532.pdf
- https://cdn-cms.f-static.net/uploads/4374371/normal_6054ba092bb90.pdf
- https://static.s123-cdn-static.com/uploads/4455376/normal_5ffc1914b301b.pdf
- https://nirawulef.weebly.com/uploads/1/3/4/3/134324477/bb075b4f.pdf
- http://noxixap.pbworks.com/f/fixixoremobaf.pdf
- http://pigedigasexu.pbworks.com/f/how_often_do_you_change_keurig_charcoal_filter.pdf
- https://miluxeto.weebly.com/uploads/1/3/5/3/135326788/9778306.pdf
- https://nopogevoxipati.weebly.com/uploads/1/3/1/4/131410158/zutarubotowo-daxino.pdf
- http://dijakezepo.pbworks.com/f/74924062187.pdf
- https://jaligudupu.weebly.com/uploads/1/3/5/3/135391073/vetewugewo.pdf
- http://bowawesup.pbworks.com/f/bepekekuxolovigeder.pdf
- https://static.s123-cdn-static-d.com/uploads/4409246/normal_60b4935fe2446.pdf
- https://cdn-cms.f-static.net/uploads/4404490/normal_603102221e70d.pdf
- http://pefumugat.pbworks.com/f/the_south_african_vegan_cookbook_download.pdf
- http://rimogeto.pbworks.com/w/file/fetch/144427854/29844620928.pdf
- https://favaruzikab.weebly.com/uploads/1/3/4/8/134871436/6204742.pdf
- https://static.s123-cdn-static-d.com/uploads/4490127/normal_60b4c91a2e4c6.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- synerhu.ru
- wekupadafar.weebly.com
- cdn-cms.f-static.net
- static.s123-cdn-static.com
- ridakikasidom.weebly.com
- sokulus.pbworks.com
- lexibitite.pbworks.com
- nirawulef.weebly.com
- noxixap.pbworks.com
- pigedigasexu.pbworks.com
- miluxeto.weebly.com
- nopogevoxipati.weebly.com
- dijakezepo.pbworks.com
- jaligudupu.weebly.com
- bowawesup.pbworks.com
- static.s123-cdn-static-d.com
- pefumugat.pbworks.com
- rimogeto.pbworks.com
- favaruzikab.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 135.233.45.223
- 172.172.255.217
- 52.110.12.22
- 4.230.171.124
- 20.165.94.63
- 135.232.92.97
- 52.123.128.14
- 20.184.175.13
- 72.154.7.96
- 203.26.79.13
- 135.234.160.247
- 74.178.76.44
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report