MALICIOUS — a1dbd0c58e3e4d56aaf87d98dd3787882d180901ee379f6a708e08d1541fa82a
MALICIOUS — a1dbd0c58e3e4d56aaf87d98dd3787882d180901ee379f6a708e08d1541fa82a is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
a1dbd0c58e3e4d56aaf87d98dd3787882d180901ee379f6a708e08d1541fa82a - SHA-1:
f1ea3335476851cfe8bade18346348e431e5e4de - MD5:
fa38e2c8d51043d19eb18ebdc6a3fdf9 - ssdeep:
1536:7pTUygWHXn0eQyXRRUQID/Dn0SAg5lmp9nxYlPTVo8zISWxH8HEmGM0jW8pO+9Dt:dQygWH3FBRZWnmvpBxY7o8zIXH8H3d0X - TLSH:
T17038C1F3225BDD8C7A5ADB47A9DA126C544EEBC82132F9E05149B67C84FC97CAF00610 - Submitted as: a1dbd0c58e3e4d56aaf87d98dd3787882d180901ee379f6a708e08d1541fa82a
- File type: pdf · Size: 81057 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://smeeing.com/userfiles/files/befaledixova.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 16 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://catamma.ru/uplcv?utm_term=letter+without+return+address, https://www.dyna-tech.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1609455f383aa6---37839427235.pdf, https://www.tctnanotech.com/wp-content/plugins/super-forms/uploads/php/files/2609f6515051c101242e871429227dfb/rotuzamomiji.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9718 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
4e77415826a7be648e788cc153207d91a260b54df5f75180a08471f3b215673b - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\2fe84e9d87dc097e978e5bed7a10b645.png -
b4aa526e92e0be1dfb44353d9b3a6faa1588e128fe485a6dcf88b8b55c9afcc9 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://catamma.ru/uplcv?utm_term=letter+without+return+address
- https://www.dyna-tech.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1609455f383aa6---37839427235.pdf
- https://www.tctnanotech.com/wp-content/plugins/super-forms/uploads/php/files/2609f6515051c101242e871429227dfb/rotuzamomiji.pdf
- https://veritiesinstitute.com/wp-content/plugins/super-forms/uploads/php/files/aa7c1d235f3ec15b33b646ec785dcf53/masasetal.pdf
- http://smeeing.com/userfiles/files/befaledixova.pdf
- http://icltindia.in/userfiles/file/73733140719.pdf
- http://bergfin.se/wp-content/plugins/formcraft/file-upload/server/content/files/160ec5141bbb11---63908016942.pdf
- https://atx-stroy.ru/wp-content/plugins/super-forms/uploads/php/files/886569fb67340cc5b178c7f607f762f7/dusugurabub.pdf
- http://ytovietnam.net/ckfinder/userfiles/files/vovovew.pdf
- https://www.infrascale.com/wp-content/plugins/super-forms/uploads/php/files/2d9b12d84ec26cedb347a50b1b0d1f0e/88262887304.pdf
- https://mkontakt.pl/dat//file/jezusagel.pdf
- https://yuss.itfile/senuzegeximixo.pdf
- https://eandjfamilyhealthcenter.com/wp-content/plugins/super-forms/uploads/php/files/908c03e909f9fc57d1eefab60401beab/napomufoposanovisame.pdf
- http://averon.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1608c0f27681bf---kitetawofiwaratakik.pdf
- https://aguiapromocional.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160df710dbccb9---73826728889.pdf
- https://moniimpex.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608a58bbeb6ce---supumebuwuvezebeka.pdf
- http://wrtour.com/FileData/ckfinder/files/20210730_3839E38F7B3FCE8A.pdf
- http://travelspace.pl/userfiles/file/kuwugutamum.pdf
- http://botanicgardenscafe.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/160b898be2003d---24732009043.pdf
- https://5udua.com/contents//files/vadojakig.pdf
- https://panama4d.com/contents//files/kokumanovoboga.pdf
- http://amblesidewindermere.ca/fckuploads/images/file/44288010493.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- catamma.ru
- www.dyna-tech.nl
- www.tctnanotech.com
- veritiesinstitute.com
- smeeing.com
- icltindia.in
- bergfin.se
- atx-stroy.ru
- ytovietnam.net
- www.infrascale.com
- mkontakt.pl
- eandjfamilyhealthcenter.com
- averon.ca
- aguiapromocional.com.br
- moniimpex.com
- wrtour.com
- travelspace.pl
- botanicgardenscafe.com.au
- 5udua.com
- panama4d.com
- amblesidewindermere.ca
- www.w3.org
- purl.org
- ns.adobe.com
- yuss.itfile
Embedded IP addresses
- 52.110.12.45
- 4.230.171.124
- 20.247.184.197
- 74.178.76.128
- 135.233.95.135
- 40.99.133.210
- 52.123.129.14
- 135.233.45.223
- 57.155.101.212
- 74.178.232.29
- 203.26.79.13
- 52.123.252.239
- 92.223.78.30
- 40.79.163.155
- 172.175.111.170
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report