MALICIOUS — b88ee360187be36a69cd2625f0e51cf11e892009f05f9e07e4e3979cd08012e0
MALICIOUS — b88ee360187be36a69cd2625f0e51cf11e892009f05f9e07e4e3979cd08012e0 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
b88ee360187be36a69cd2625f0e51cf11e892009f05f9e07e4e3979cd08012e0 - SHA-1:
54c567569183218dd9522f426fa5c5aa0bd5ea58 - MD5:
971071fe1e71bb2c83e64f4c3db15a18 - ssdeep:
1536:XhLBgWNWbyfKsVftO/HFNHPNtpSf+OgURGA7/6NaRcxMNHWapOtQOBEzhW0L8Z70:RBrr3O/7FrS2lU4zxgotQBzLE7iJL9 - TLSH:
T1853AC1F321D3DD8C774ECB0759E621A8608AD3446071EAA00589BBACE4BC9BD7F50D61 - Submitted as: b88ee360187be36a69cd2625f0e51cf11e892009f05f9e07e4e3979cd08012e0
- File type: pdf · Size: 96694 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 18 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://vargyasnekonyveles.hu/kepek/other/file/zenipinosi.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://vargyasnekonyveles.hu/kepek/other/file/zenipinosi.pdf, http://tevukasveza.lt/ckfinder/userfiles/files/69259912477.pdf, http://suliaok.com/v15/Upload/file/2021912133643461.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9749 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
90da4ae76031474b4e659541dea7106d875d57410f35a220e37758d2069ba5ef - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\e8a7012917cc062a8749cca2ec8d6b7a.png -
cf9a92e47eec8af488371728cb5484835ab12bd190f6741f7f795e8ca4b28f83 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/S30rS-6n6vg/uplcv?utm_term=write+a+cosine+function+for+the+graph
- https://vargyasnekonyveles.hu/kepek/other/file/zenipinosi.pdf
- http://tevukasveza.lt/ckfinder/userfiles/files/69259912477.pdf
- http://suliaok.com/v15/Upload/file/2021912133643461.pdf
- https://medarbindia.org/ckfinder/userfiles/files/16358563014.pdf
- https://hafa-verein.de/wp-content/plugins/super-forms/uploads/php/files/e9629fd7340062464a1c60c5e04900d1/wuxasatuzirujavinop.pdf
- http://mingmitrcoffee.com/user_img/files/73915006920.pdf
- http://dogalakustik.com/depo/sayfaresim/file/70995466942.pdf
- https://xeroxexpres.cz/userfiles/file/67403226375.pdf
- http://jplus-ag.com/upload/files/BodyFile__613E09518F438.pdf
- https://testgit.begurholidays.com/uploads/userfiles/files/35541652973.pdf
- http://5mal4.de/moneyvidya/web/images/userfiles/file/58449382199.pdf
- http://se-ty.com/uploads/userfiles/file/mebonu.pdf
- https://hankilfood.com/upfile/files/10767407348.pdf
- http://wittymall.com/multimedia/userfiles/file/6525898270.pdf
- https://ballestermultiservicios.com/wp-content/plugins/formcraft/file-upload/server/content/files/16135c86f6f61d---43432423548.pdf
- https://marblobathware.com/app/webroot/img/files/22044683554.pdf
- https://sarenpinler.com/calisma2/files/uploads/13481654067.pdf
- http://verypool.cn/images/upload/File/rasulojibefopoxuzuk.pdf
- https://event-connections.net/wp-content/plugins/formcraft/file-upload/server/content/files/1612f43a8eafbc---51780022078.pdf
- https://kovrdom.ru/sites/all/sites/default/files/file/nubefizapawatat.pdf
- https://bitree.com/ckfinder/userfiles/files/xajubiwugenidakil.pdf
- http://rabotatver.ru/userfiles/admin/nezora.pdf
- http://arcenevents.nl/site/upload/files/13016649132.pdf
- https://flyags.com/editorResources/file///luvabizo.pdf
Embedded domains
- feedproxy.google.com
- suliaok.com
- medarbindia.org
- hafa-verein.de
- mingmitrcoffee.com
- dogalakustik.com
- jplus-ag.com
- testgit.begurholidays.com
- 5mal4.de
- se-ty.com
- hankilfood.com
- wittymall.com
- ballestermultiservicios.com
- marblobathware.com
- sarenpinler.com
- verypool.cn
- event-connections.net
- kovrdom.ru
- bitree.com
- rabotatver.ru
- arcenevents.nl
- flyags.com
- ymy-tea.tw
- myxroad.net
- www.w3.org
Embedded IP addresses
- 57.155.101.212
- 52.168.112.66
- 172.172.255.217
- 74.178.240.61
- 74.179.71.159
- 52.123.252.220
- 52.230.60.54
- 52.110.12.37
- 52.110.12.53
- 4.230.171.124
- 135.232.92.137
- 52.138.229.67
- 20.112.250.133
- 52.123.129.14
- 203.26.79.13
- 74.178.76.44
- 4.150.223.105
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report