MALICIOUS — a9b9b0e2702e93c670fb723270ea542e1f554db36a9371df1a72657081fd7178
MALICIOUS — a9b9b0e2702e93c670fb723270ea542e1f554db36a9371df1a72657081fd7178 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
a9b9b0e2702e93c670fb723270ea542e1f554db36a9371df1a72657081fd7178 - SHA-1:
cd4d7cc3d047c640766c958ae80d4d9ee6a5454f - MD5:
7660bafa80e8df4ba510b502bdbee181 - ssdeep:
1536:skmzHK414uYi0DMHGMYiC9v/eIO4AENEngVHrhSTF1xgnJL7:N/cT0IHGTiC9v/JfAENEuLhSp1xIJ - TLSH:
T1DB38C0F36197CD8CB5996B03B9E6840C614AC38D7131EFA144C4FBACC5BD6AD2E11A12 - Submitted as: a9b9b0e2702e93c670fb723270ea542e1f554db36a9371df1a72657081fd7178
- File type: pdf · Size: 79063 bytes
- Verdict: malicious (98/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!7660BAFA80E8
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/6134c928-e985-4b5f-9df6-c5f9a23247fc/somewhere_over_the_rainbow_ukulele_easy_play_along.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 16 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://chcial.ru/pbw?utm_term=free+download+vlc+1.7+5+apk+for+android+2.3, http://volikedejefa.pbworks.com/f/kojelugetafaw.pdf, http://wuranosa.pbworks.com/f/sotozaje.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9697 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787923582&P2=404&P3=2&P4=KdeJJbkJzBotYi88pmtyLYLyUnB3mns5qtwmrIyYEtXTNW9Khv24V61K74jryWItyYJg4XB4simSH%2f0dkeu4HA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787923623&P2=404&P3=2&P4=aN1XPRoBvg33GWqYr7ItGN%2foE5Hj96mLsazfDYKfBu0T3%2f%2fqxcQoFRLpDuq1GeVwf1uKcVQmWkAzBrOywfGLVQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
fdc09ac09889a63ffffa24753aeeb69724c21cc3906e1a655cc891440eff330e - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\954b70e79a9af69c740db41350c5a19f.png -
6931dbc1a7fcd06842d9fd72a8a5d49a97d740925d08129adc65c6805192c23f - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://chcial.ru/pbw?utm_term=free+download+vlc+1.7+5+apk+for+android+2.3
- http://volikedejefa.pbworks.com/f/kojelugetafaw.pdf
- http://wuranosa.pbworks.com/f/sotozaje.pdf
- http://bovojigu.pbworks.com/w/file/fetch/144420204/baby_corn_snake_feeding_schedule.pdf
- https://uploads.strikinglycdn.com/files/6134c928-e985-4b5f-9df6-c5f9a23247fc/somewhere_over_the_rainbow_ukulele_easy_play_along.pdf
- https://garugufalavul.weebly.com/uploads/1/3/4/5/134507034/7926011.pdf
- https://uploads.strikinglycdn.com/files/8af02575-dc37-4f44-baed-56a3b2cc5522/how_to_program_genie_garage_door_remote_acsctg_type_2.pdf
- https://uploads.strikinglycdn.com/files/25dd4abf-1c9a-4a8e-86b5-7a2b7ac94950/sample_letter_of_recommendation_for_management_position.pdf
- http://kolelulu.pbworks.com/f/arunachalam_tamil_movie_download_tamilyogi.pdf
- http://xoxafepapesu.pbworks.com/f/screen_recorder_with_facecam_and_audio_video_editor_apk.pdf
- http://funinupun.pbworks.com/f/short_book_review_of_treasure_island.pdf
- https://uploads.strikinglycdn.com/files/361ac62f-3fc8-441f-ab69-3f49fa9a44ce/realtek_audio_drivers_download_for_pc_64_bit.pdf
- http://lugozamuxika.pbworks.com/f/2530776115.pdf
- http://kapetipubi.pbworks.com/w/file/fetch/144421644/un_lugar_en_silencio_2_fecha_de_estreno_peru.pdf
- http://kedetuwi.pbworks.com/w/file/fetch/144419445/bootable_usb_not_detected_macbook_pro.pdf
- https://uploads.strikinglycdn.com/files/26d66d78-cfd1-4e48-93f9-1442a050da91/how_often_change_braun_series_7_head.pdf
- http://zopujoxobug.pbworks.com/f/26708456432.pdf
- https://jumitugiputetiv.weebly.com/uploads/1/3/5/3/135313018/zomapeguludoxov-gedagoritibapo-kagozegedezerex-kuraz.pdf
- http://xojifot.pbworks.com/f/fufabo.pdf
- http://sizolasipape.pbworks.com/f/sezejejazesuxenusuwulax.pdf
- http://negovijalulu.pbworks.com/w/file/fetch/144412272/how_to_hack_asphalt_9_on_android.pdf
- http://zemenifinabe.pbworks.com/f/sq11_mini_dv_kamera_app.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- chcial.ru
- volikedejefa.pbworks.com
- wuranosa.pbworks.com
- bovojigu.pbworks.com
- uploads.strikinglycdn.com
- garugufalavul.weebly.com
- kolelulu.pbworks.com
- xoxafepapesu.pbworks.com
- funinupun.pbworks.com
- lugozamuxika.pbworks.com
- kapetipubi.pbworks.com
- kedetuwi.pbworks.com
- zopujoxobug.pbworks.com
- jumitugiputetiv.weebly.com
- xojifot.pbworks.com
- sizolasipape.pbworks.com
- negovijalulu.pbworks.com
- zemenifinabe.pbworks.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 20.42.73.30
- 20.42.65.84
- 52.123.252.248
- 20.42.179.192
- 52.110.12.18
- 4.230.171.124
- 4.144.132.223
- 74.179.77.204
- 52.123.128.14
- 92.223.78.30
- 135.233.95.80
- 203.26.79.13
- 135.233.45.221
- 4.207.44.65
- 48.200.63.27
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report