MALICIOUS — a90a8fbe7fa9e801a4d2e751a10462219e0ce43c92ea5c75feaa91d31c3d550e
MALICIOUS — a90a8fbe7fa9e801a4d2e751a10462219e0ce43c92ea5c75feaa91d31c3d550e is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
a90a8fbe7fa9e801a4d2e751a10462219e0ce43c92ea5c75feaa91d31c3d550e - SHA-1:
cfded521d96b071ada1ed8b08ac64fad3ecc50b4 - MD5:
5a1750bce2ba144063e449af8ef0cd55 - ssdeep:
1536:Kso2AIw4MjyfPOktkoaT9XxyATS/Pc9dH0/GxBw4QJeiubiPJbtQ9RixWd8yvuPb:sqvm9x6/4xBmohStQ9RixWd8CS - TLSH:
T1A637CFF36057DC4C7A8B2B43ADE6061E65EEC3CCB1318BA15888B62D95AC7ED7E10510 - Submitted as: a90a8fbe7fa9e801a4d2e751a10462219e0ce43c92ea5c75feaa91d31c3d550e
- File type: pdf · Size: 76049 bytes
- Verdict: malicious (98/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!5A1750BCE2BA
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/5216514d-edc0-44f2-a0d1-dc6fca8e110c/kalulur.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 20 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://crysiq.ru/pbw?utm_term=verbals+exercises+with+answers, http://mosijiv.pbworks.com/w/file/fetch/144749856/job_resignation_letter_format_in_marathi.pdf, http://poxanoralanu.pbworks.com/w/file/fetch/144426492/tamil_comedy_movies_2016_free_download_in_tamilrockers.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (14 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9655 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\206fa26c59972d55393e88b6887193d5.png -
a127827e4f158ca47fc8d621eaab2562cdc392e90a2df38b489fe6e1192a8767 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
7c1b89b5bc4f2287e8a7620b8ac29a2991aecbf44a1b4572eb870b0ab45df206 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://crysiq.ru/pbw?utm_term=verbals+exercises+with+answers
- http://mosijiv.pbworks.com/w/file/fetch/144749856/job_resignation_letter_format_in_marathi.pdf
- http://poxanoralanu.pbworks.com/w/file/fetch/144426492/tamil_comedy_movies_2016_free_download_in_tamilrockers.pdf
- https://uploads.strikinglycdn.com/files/5216514d-edc0-44f2-a0d1-dc6fca8e110c/kalulur.pdf
- https://robesiso.weebly.com/uploads/1/3/4/5/134501854/wemegifigab-darimikuj-zupudumen.pdf
- https://xafudilolara.weebly.com/uploads/1/3/4/7/134744509/gixubab.pdf
- https://uploads.strikinglycdn.com/files/c4c40622-bdaf-4dc4-a63f-99467a0c3e2f/sekenapidiku.pdf
- https://relabibede.weebly.com/uploads/1/3/2/8/132816075/jimovupide.pdf
- https://uploads.strikinglycdn.com/files/977dc2e2-dbfb-4352-8131-7fb2003cdced/punafenasoromudosopikifet.pdf
- https://uploads.strikinglycdn.com/files/9f27f185-05d7-40cf-bc27-f441da445f30/71638727509.pdf
- https://uploads.strikinglycdn.com/files/81102c2d-8b51-47f0-b854-7809035b4318/something_the_beatles_sheet_music.pdf
- http://xuresasadox.pbworks.com/w/file/fetch/144668598/huawei_y3_2020_frp_bypass_apk_download_for_android.pdf
- https://jukirabupunux.weebly.com/uploads/1/3/0/8/130874410/wuseku-jajosaw.pdf
- https://guzonodet.weebly.com/uploads/1/3/4/7/134724569/gedetuvutab_zarekagepabefiz.pdf
- http://wotasaful.pbworks.com/f/among_us_cartoon_cat_mod_apk.pdf
- https://uploads.strikinglycdn.com/files/b55aff99-6ead-40ee-b54d-12270c5e01ee/all_about_love_bell_hooks_book_depository.pdf
- https://cdn-cms.f-static.net/uploads/4374700/normal_605910b20a71d.pdf
- https://static.s123-cdn-static.com/uploads/4447433/normal_6002130671f86.pdf
- https://uploads.strikinglycdn.com/files/61227c4c-7283-4b40-9a85-e1c84e6dfb70/72640805658.pdf
- https://vupikesuxal.weebly.com/uploads/1/3/4/3/134397623/1194830.pdf
- https://cdn-cms.f-static.net/uploads/4367310/normal_60bfb338eb1b7.pdf
- https://uploads.strikinglycdn.com/files/e9787672-bbdf-4563-96a6-f5b68b92ec50/multiplying_and_dividing_fractions_worksheets.pdf
- https://uploads.strikinglycdn.com/files/94bc0390-85d5-4ef7-bedf-2f9503716109/hatha_yoga_vinyasa_flow.pdf
- http://mikabipi.pbworks.com/w/file/fetch/144640716/how_to_replace_drain_hose_on_fisher_and_paykel_dishdrawer.pdf
- https://cdn-cms.f-static.net/uploads/4426816/normal_606df3d818312.pdf
Embedded domains
- crysiq.ru
- mosijiv.pbworks.com
- poxanoralanu.pbworks.com
- uploads.strikinglycdn.com
- robesiso.weebly.com
- xafudilolara.weebly.com
- relabibede.weebly.com
- xuresasadox.pbworks.com
- jukirabupunux.weebly.com
- guzonodet.weebly.com
- wotasaful.pbworks.com
- cdn-cms.f-static.net
- static.s123-cdn-static.com
- vupikesuxal.weebly.com
- mikabipi.pbworks.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 162.159.142.9
- 40.74.98.196
- 52.110.12.4
- 74.178.232.29
- 57.154.63.210
- 4.230.171.124
- 72.153.5.129
- 4.144.132.223
- 203.26.79.13
- 20.165.94.63
- 4.150.223.97
- 20.112.250.133
- 92.223.78.30
- 52.123.128.14
- 40.104.4.2
- 135.234.160.245
- 20.42.73.25
- 172.170.180.133
- 20.42.65.90
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report