MALICIOUS — kidomor.pdf
MALICIOUS — kidomor.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
9aecc1c9094c6918e3602286ca07e3fa8fa2a26bdb14f32684a5c85df7086378 - SHA-1:
f16c9fe24e015f1b2890c7fbedfa8c408aaebea2 - MD5:
5bc6ea6c08597c6024373973070cd9b4 - ssdeep:
1536:P6G4ka4iYDT1eZOsBnNJglJ9S3Xfhd3UPvrnZcA7qLstioYWby4b7baSP1xfXtQr:GMDT1tsVgl/S3XfhdEPrZkg/b97bPP7a - TLSH:
T1FF39D0F72057DD4C7ACA9F4B4ABE01AC2189D3C86063DA904489B76CC47D6BDAF106A1 - Submitted as: kidomor.pdf
- File type: pdf · Size: 87873 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://panama4d.com/contents/files/muxodekulugu.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 16 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://portamarioarchitetto.eu/userfiles/files/8536105538.pdf, http://paintingservicesonline.ca/wp-content/plugins/formcraft/file-upload/server/content/files/161328fcb43bc1---sarasa.pdf, https://raljob.com/userfiles/file/wexaze.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9822 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- _dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787772491&P2=404&P3=2&P4=WjORHzVFdYaxt8q%2bhDK%2fUkvXL9gripfmrGM%2bC8wRRmbAHdy%2f0nCW24NWj1sJF9WUMx2C8o0%2fR4Hvh4iwTqTzBA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
724622b8ee673eff70dd4694172da3de188f6973375a2b2cdc39a59b80688a48 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\b4d1f9cb1dbd98925b1f9cf42a8e6eb1.png -
49e5a00f747a36a20b255a17e88fadf2520beb24fe175dc82488342ff0077d19 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/BvfzZFkJO3s/uplcv?utm_term=usb+setting+transfer+media+files
- http://portamarioarchitetto.eu/userfiles/files/8536105538.pdf
- http://paintingservicesonline.ca/wp-content/plugins/formcraft/file-upload/server/content/files/161328fcb43bc1---sarasa.pdf
- https://raljob.com/userfiles/file/wexaze.pdf
- https://panama4d.com/contents/files/muxodekulugu.pdf
- https://www.hs-hofgastein.salzburg.at/ckfinder/userfiles/files/karixavasatufuverote.pdf
- https://rwd.webseo.tw/upload/files/tebopudeno.pdf
- https://firsatpin.com/calisma2/files/uploads/bejetisitote.pdf
- https://www.drserapkagan.com/wp-content/plugins/super-forms/uploads/php/files/2qnqtesjkll0i4hl0rsoaaejmq/43024017543.pdf
- http://poddertradingandindustries.com/userfiles/file/16946598606.pdf
- https://ringid.vn/ckfinder/userfiles/files/95032601823.pdf
- http://secretinvitation.net/images/files/25122315963.pdf
- https://rhythmcprandfirstaid.com/wp-content/plugins/super-forms/uploads/php/files/37aed45ce285d9e155e23d7b207fce4d/62874966219.pdf
- http://localhomesales.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16134f6e8af41f---58183117615.pdf
- http://structurecreative.com/wp-content/plugins/formcraft/file-upload/server/content/files/161320878eb6ce---pinuliraru.pdf
- http://www.phsdcenter.com/temp/js/ckfinder/userfiles/files/zupadekiburezisetipo.pdf
- https://greenvalleykerala.com/ckfinder/userfiles/files/sepaxevi.pdf
- https://aymsoft.us/aym_image/files/xananufamakuwekerabew.pdf
- https://mygamedaysports.com/wp-content/plugins/super-forms/uploads/php/files/64b7e5f419ffa2efc55b4d46a45f04d5/25431743265.pdf
- https://biothiennam.com/media/ftp/file/rewulo.pdf
- https://hygradeinsulators.com/images/uploads/file/18075901442.pdf
- http://eko-uklid.com/files/file/12751662102.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- feedproxy.google.com
- portamarioarchitetto.eu
- paintingservicesonline.ca
- raljob.com
- panama4d.com
- rwd.webseo.tw
- firsatpin.com
- www.drserapkagan.com
- poddertradingandindustries.com
- secretinvitation.net
- rhythmcprandfirstaid.com
- localhomesales.com.au
- structurecreative.com
- www.phsdcenter.com
- greenvalleykerala.com
- aymsoft.us
- mygamedaysports.com
- biothiennam.com
- hygradeinsulators.com
- eko-uklid.com
- www.w3.org
- purl.org
- ns.adobe.com
- www.hs-hofgastein.salzburg.at
- ringid.vn
Embedded IP addresses
- 74.178.232.29
- 20.42.179.192
- 52.123.252.238
- 52.110.12.45
- 40.84.85.40
- 4.230.171.124
- 52.230.59.222
- 52.168.112.66
- 20.236.44.162
- 74.178.240.61
- 52.123.129.14
- 135.233.45.223
- 20.165.94.46
- 203.26.79.13
- 135.234.160.246
- 48.200.63.27
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report