MALICIOUS — ab0a543e991cac3de500d0b8459665c23f43faf8c6a42e8d1f3f6fbe595ab17d
MALICIOUS — ab0a543e991cac3de500d0b8459665c23f43faf8c6a42e8d1f3f6fbe595ab17d is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
ab0a543e991cac3de500d0b8459665c23f43faf8c6a42e8d1f3f6fbe595ab17d - SHA-1:
30e201e56e2a80de3efb6ead1bfd3e0a7803b986 - MD5:
ddce2de3802567c0a7d32b833b1d3eef - ssdeep:
1536:VTjl7u2Wm57IJ2IQ655DC3Q/JEF6W/mRrmWWspORv9ntrQ2aU:HSJ2I7aQRGFkmJRvLQA - TLSH:
T14238AFF32197ED8C764B9F43B9BA126C9496D6841122EF504488BB3C867C9BD7F04742 - Submitted as: ab0a543e991cac3de500d0b8459665c23f43faf8c6a42e8d1f3f6fbe595ab17d
- File type: pdf · Size: 76962 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://benevolo.it/userfiles/files/pizodovovanesiboxu.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 17 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://benevolo.it/userfiles/files/pizodovovanesiboxu.pdf, http://german-ex.com/images/blog/file/wejatudosisowedat.pdf, http://luckyassessoria.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1613bd7dc6e693---19328218685.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9678 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787859053&P2=404&P3=2&P4=f%2b3pTER84OyffrDSNFlPd0CeZg5s6DfpouAqMELoMwATnOXs%2b7xeUJyCU1jpRd4ZNXZGt%2fnZUTJYpgolZNaD7A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787859116&P2=404&P3=2&P4=SZ95v7I4dhYM4ZziHiOZXPnwofuA8NirtWmG9WD6XfJsCTa3A8bUEIoTOwSwGeraSBJYJR8lyalLqmvEzIjsrg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787255809&P2=404&P3=2&P4=MzTWwq3%2fNm%2bnQdKi1T14smR73gnFRtHjt1hvOslPTlD%2b88IbQ80lwC5X4FdsyzPZqqKOXMDYH%2fzq2NXZj9lirw%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\05d40727faa47c0f838b43474bbd955c.png -
4cf44f10e9fb899280d1905d6b82525955e62b298464acaa969456ef8c25d376 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
25b422b7887e67a4f89a70242b97e42edf22dea081e2c2c4a04cbb016c25cf66 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/3CAf4wW3hvY/uplcv?utm_term=kickin+it+season+4+123movies
- http://benevolo.it/userfiles/files/pizodovovanesiboxu.pdf
- http://german-ex.com/images/blog/file/wejatudosisowedat.pdf
- http://luckyassessoria.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1613bd7dc6e693---19328218685.pdf
- http://bwemfjhjk.friend-match.com/upload/files/zunorezuxuw.pdf
- http://jlsxjy.com/right/UploadFile/file///2021091105021073499.pdf
- http://tsrmmessina.it/userfiles/files/61774697402.pdf
- https://mkserwis.pl/userfiles/file/15966568223.pdf
- http://icbiz.ru/userfiles/file/94284716958.pdf
- https://office-agglo-larochelle.fr/userfiles/file/6501941348.pdf
- https://www.bussmann-tiefbau.de/ckfinder/userfiles/files/71459092506.pdf
- https://jurvamartin.com/userfiles/file/4782180540.pdf
- http://karcannakliyat.com/userfiles/file/40402408860.pdf
- http://sanarina-coaching.de/ckfinder/userfiles/files/60525488601.pdf
- http://intechsol.kz/wp-content/plugins/formcraft/file-upload/server/content/files/1613b80113af05---liwag.pdf
- http://princeworldwide.com/multimedia/userfiles/file/xesigenenakolajemuriwe.pdf
- http://miyagi.chi-kara.net/Upload/files/lagezujefizunibakujegew.pdf
- http://challendor.com/fckeditor/upload/file/30922639581.pdf
- http://bajajsports.com/userfiles/file/35779726355.pdf
- https://immsac.pe/sgi_userfiles/userfiles/files/15050577212.pdf
- http://luckyassessoria.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1613aaeb88b96e---77622487432.pdf
- https://cdmsig1.com/ckfinder/userfiles/files/sepetiz.pdf
- https://infravoip.com/wp-content/plugins/super-forms/uploads/php/files/e75a3ab3fae3c8ea7e35a11d967326b2/labipibegasugozodonu.pdf
- https://ourguarantees.com/userfiles/file/23914077117.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- benevolo.it
- german-ex.com
- luckyassessoria.com.br
- bwemfjhjk.friend-match.com
- jlsxjy.com
- tsrmmessina.it
- mkserwis.pl
- icbiz.ru
- office-agglo-larochelle.fr
- www.bussmann-tiefbau.de
- jurvamartin.com
- karcannakliyat.com
- sanarina-coaching.de
- princeworldwide.com
- miyagi.chi-kara.net
- challendor.com
- bajajsports.com
- cdmsig1.com
- infravoip.com
- ourguarantees.com
- www.w3.org
- purl.org
- ns.adobe.com
- intechsol.kz
Embedded IP addresses
- 52.123.252.227
- 52.110.12.40
- 85.210.193.152
- 4.230.171.124
- 52.230.60.54
- 135.233.95.144
- 20.184.175.18
- 74.178.76.54
- 20.76.201.171
- 203.26.79.13
- 52.123.129.14
- 135.233.45.223
- 52.123.252.220
- 20.165.94.46
- 57.155.104.224
- 4.209.250.170
- 20.184.175.0
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report