MALICIOUS — a4070b6f1011d5849481a871fc23b15e4b725148e6e7ae1e41d3982ac893a76a
MALICIOUS — a4070b6f1011d5849481a871fc23b15e4b725148e6e7ae1e41d3982ac893a76a is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
a4070b6f1011d5849481a871fc23b15e4b725148e6e7ae1e41d3982ac893a76a - SHA-1:
4c02eab6da7eca93b1ae6724dcceeff8e3e0699c - MD5:
416d954676ed25596d3325c49887486c - ssdeep:
1536:9MYX2y4nlsiPSiauN8aveOt+UqFNi+RJyZXCj2uWspORGWJfM04OGZWrnXZ5PY:gy4nweNFpsUWNi+REZXCj2BR3fMOf4 - TLSH:
T18037C0F360A7ED9DB399AF07ADB701AC644AD38C5172DE50508CBA2C907C9BDAF10601 - Submitted as: a4070b6f1011d5849481a871fc23b15e4b725148e6e7ae1e41d3982ac893a76a
- File type: pdf · Size: 72943 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://joeun-it.com/userData/board/file/jopimemepanoxef.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 17 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://coretry.ru/uplcv?utm_term=field+runners+2+apk, http://joeun-it.com/userData/board/file/jopimemepanoxef.pdf, https://megalightgroup.lv/uploads/files/doruk.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9765 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
85aba98eaf81ec4a9d4ed3a2291a9b1ddd40c3f44b28748aa5e2c56a5682df44 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\dc0a6e08958a48960f21b97f7bb088b7.png -
543c588d03dde89c098ec569d67d8f08b4237118a47e03d56c4de9171b219d02 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://coretry.ru/uplcv?utm_term=field+runners+2+apk
- http://joeun-it.com/userData/board/file/jopimemepanoxef.pdf
- https://megalightgroup.lv/uploads/files/doruk.pdf
- https://yidinfo.net/wp-content/plugins/super-forms/uploads/php/files/lndekrpd6303ee2lqc1rque2ld/41397921730.pdf
- https://jungleflightchiangmai.jungle-flight.com/Uploads/files/wujigotijagefinu.pdf
- http://innersolutions-uk.com/file/56297534385.pdf
- http://cl-pub.com/files/files/50521710440.pdf
- https://mvpartners.be/images/uploadedimages/file/77006036252.pdf
- https://thieumaunao.vn/workspace/develop/uploads/ck_upload/files/15161560616.pdf
- https://hattoco.vn/images/ckeditor/files/49194720792.pdf
- http://ovartec.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613413e15144e---3175597135.pdf
- https://amgaa.org/temp/files/69389414791.pdf
- http://ebonit.light.bg/includes/libs/ckfinder/userfiles/files/67794714301.pdf
- http://relaxzenter.com/uploads/files/26918959315.pdf
- https://luckyfood.itweald.com/uploads/files/61436e39a0be1.pdf
- http://archbot.pl/files/file/1574299546.pdf
- https://olivier-daulte.com/ckfinder/userfiles/files/tisototujegogutulimako.pdf
- https://californiaoptionsrealestate.com/wp-content/plugins/super-forms/uploads/php/files/2a7a88edde01f895b20ce94e285fdba9/nigukisinu.pdf
- http://denda.co.kr/ckfinder/userfiles/files/6774181029.pdf
- http://poltinka.ru/userfiles/file/zemekebidilabenazifekifa.pdf
- https://beaszemin.com/files/9330609674.pdf
- https://irrisyst.eu/files/file/68966897465.pdf
- http://app0.linkeo.it/ckfinder/userfiles/files/76981895162.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- coretry.ru
- joeun-it.com
- yidinfo.net
- jungleflightchiangmai.jungle-flight.com
- innersolutions-uk.com
- cl-pub.com
- mvpartners.be
- ovartec.com
- amgaa.org
- relaxzenter.com
- luckyfood.itweald.com
- archbot.pl
- olivier-daulte.com
- californiaoptionsrealestate.com
- denda.co.kr
- poltinka.ru
- beaszemin.com
- irrisyst.eu
- app0.linkeo.it
- www.w3.org
- purl.org
- ns.adobe.com
- megalightgroup.lv
- thieumaunao.vn
- hattoco.vn
Embedded IP addresses
- 52.123.252.235
- 52.110.12.54
- 52.110.12.44
- 85.210.193.152
- 4.230.171.124
- 4.150.223.107
- 20.231.239.246
- 135.232.92.137
- 52.123.128.14
- 40.103.64.226
- 135.233.45.223
- 135.233.95.80
- 203.26.79.13
- 92.223.78.30
- 57.155.101.212
- 13.89.179.12
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report