MALICIOUS — b215c9db02ec389011caacddc41c6ef6c8bcc966b2f92bbe998c0b7852a4f448
MALICIOUS — b215c9db02ec389011caacddc41c6ef6c8bcc966b2f92bbe998c0b7852a4f448 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
b215c9db02ec389011caacddc41c6ef6c8bcc966b2f92bbe998c0b7852a4f448 - SHA-1:
2bb0c323b616b2ea26a61204dd3d400137256bfa - MD5:
a348c269a0c777f434b3a00f91597c17 - ssdeep:
1536:rK+BWosoT+ANqsYGuje4KVMKlWo3W8Br1AUlpv9y5Qc4bo2aKiWapOtQHWCbh+nx:vUoT+ANq5Guje7yJypX9y5tQo2autQnM - TLSH:
T11138DFF3619BED4CB6478B4369FB00A8A08AD7CC2171DA914148B32CD57C9BDBE04E61 - Submitted as: b215c9db02ec389011caacddc41c6ef6c8bcc966b2f92bbe998c0b7852a4f448
- File type: pdf · Size: 80082 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 17 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://momentous-inst.com/uploads/image/files/85900603791.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://caratow.nl/userfiles/file/95379739282.pdf, http://bsbcarpet.com/userfiles/file/39496376455.pdf, http://phaptangpgvn.net/app/webroot/upload/files/bawiketar.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9711 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787802933&P2=404&P3=2&P4=Drs2dD7%2b93ZyaIvp4utQCGlau%2bNJhnnVvXzUSyYYBwq3aKGU2vMHpX06b0kJNx7mEnpk1VAyPGR%2brnc26fX%2bTg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787802983&P2=404&P3=2&P4=CC%2fQSgE6BDqwbsI2aC85vXSSTxYQctpFWdjnDWztNBamT8wd6tnplIDcjZP6G4eejJ5WgsxwXmVVXd1fAvrzXw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\932174e18bf3f958fb0410a3d3c1f4dc.png -
8c47e2f20fa99e6433b9066a2738ddf714a69371eb7b645838fbd0695ca9a44a - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
e41e0a3e342a9f1811ffe52a8a276874a3138bb1e918b8da29068b34abb97c1b - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/fzgW7-mxBc0/uplcv?utm_term=dr+driving+game+mod+apk+download
- http://caratow.nl/userfiles/file/95379739282.pdf
- http://bsbcarpet.com/userfiles/file/39496376455.pdf
- http://phaptangpgvn.net/app/webroot/upload/files/bawiketar.pdf
- https://momentous-inst.com/uploads/image/files/85900603791.pdf
- http://ratchee.com/ckfinder/userfiles/files/1099869815.pdf
- https://viajespereira.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614933ad3e89c---wimirasoduxe.pdf
- http://hkwwta.org/userfiles/boburozegugabil.pdf
- https://travels-ukraine.com/wp-content/plugins/formcraft/file-upload/server/content/files/161406b637edee---17719986008.pdf
- https://hfbee.tw/upload/ckfinder_temp/files/20211009072417.pdf
- https://avukat.dnsaktif.net/upload/files/98813095884.pdf
- http://www.a-fairys-choice.com/wp-content/plugins/formcraft/file-upload/server/content/files/16152a2c8d4a38---javuxosoneviruxavewawij.pdf
- http://tainanrup.longi.tw/uploadfiles/files/20211009_181512_6620.pdf
- http://asvpp.fr/pdf/puwanewukiso.pdf
- http://daglichtfilters.nl/ckfinder/userfiles/files/jinifalivuvekevuvowelitog.pdf
- https://longhoang.vn/upload/files/powisexijopizefapi.pdf
- http://vaynhe.com/upload/files/puvotugiwixalu.pdf
- http://www.trisad.kz/ckfinder/userfiles/files/84072570755.pdf
- http://uticachemical.com/files/upload/files/xojotakalem.pdf
- http://ridendo.cz/files/file/xojabolawazipepobumox.pdf
- http://kaitosushisb.com/uploads/files/95042216897.pdf
- https://optimuselearningschool.aels.edu/learning/site/images/uploadfiles/36941648677.pdf
- http://cukiernia-waltar.pl/qcms/userfiles/file/figesojenurug.pdf
- http://pandoraecza.com/genelresimler/file/resujexetibenaf.pdf
- http://autavrabek.cz/obrazky/file/jukok.pdf
Embedded domains
- feedproxy.google.com
- caratow.nl
- bsbcarpet.com
- phaptangpgvn.net
- momentous-inst.com
- ratchee.com
- viajespereira.com
- hkwwta.org
- travels-ukraine.com
- hfbee.tw
- avukat.dnsaktif.net
- www.a-fairys-choice.com
- tainanrup.longi.tw
- asvpp.fr
- daglichtfilters.nl
- vaynhe.com
- uticachemical.com
- kaitosushisb.com
- optimuselearningschool.aels.edu
- cukiernia-waltar.pl
- pandoraecza.com
- kalmi.ru
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 40.79.163.154
- 52.123.252.193
- 135.232.92.34
- 52.110.12.11
- 20.247.184.142
- 4.230.171.124
- 72.154.7.103
- 203.26.79.13
- 20.42.65.94
- 74.178.240.61
- 52.123.129.14
- 40.104.4.2
- 135.234.160.245
- 20.42.65.88
- 20.184.175.21
- 20.42.65.89
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report