MALICIOUS — b98609481973dc77d2d2e103dcb7ad73de91179362f4790ea72da834e3ab3171
MALICIOUS — b98609481973dc77d2d2e103dcb7ad73de91179362f4790ea72da834e3ab3171 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b98609481973dc77d2d2e103dcb7ad73de91179362f4790ea72da834e3ab3171 - SHA-1:
63e5eba843e2dd942268a45234cc075292d12f04 - MD5:
585972c7a0fad8562c5bb4fe3875eaac - ssdeep:
1536:VYDfPhvUxULaDnG2oUF7QCvkStUkAm/jTybdGgUfEOmyZWbpONiWZh8snfQkCmm:AxvWUL4GjUF/9UUj4dGWjybNTh8G7Q - TLSH:
T1A13AD1F362A7ED8C768BDF43A9EA12A85445DB886031EBE00488B57C947C97C7F00A55 - Submitted as: b98609481973dc77d2d2e103dcb7ad73de91179362f4790ea72da834e3ab3171
- File type: pdf · Size: 94216 bytes
- Verdict: malicious (95/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 21 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://vienkiemis.lt/app/webroot/uploads/userfiles/files/xejibibebubonatafo.pdf, https://www.toptalentusa.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606d2d1682b00---fasetefugideluvagagamirar.pdf, http://panda-es.tokyo/yamituki-n/uploads/files/vepovokasawujagava.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9632 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\552189279277fea7c4fb92827cd33648.png -
dfd9f32c793ddec7e23e793eb1e4a986b5fba6746e1dda342423e5b5039db62d - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
0cb3992351768f4f1602e9af5fc336f6371af10d106611db0c9a206a625f0a9f - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/Om9ozkHLxGw/uplcv?utm_term=how+to+get+free+episode+gems+without+human+verification
- http://vienkiemis.lt/app/webroot/uploads/userfiles/files/xejibibebubonatafo.pdf
- https://www.toptalentusa.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606d2d1682b00---fasetefugideluvagagamirar.pdf
- http://panda-es.tokyo/yamituki-n/uploads/files/vepovokasawujagava.pdf
- http://libertyquad72.fr/userfiles/file/juxuwowimosuxepaf.pdf
- http://colescastle.com/clients/875019/File/liwomisil.pdf
- https://edukiya.com/wp-content/plugins/super-forms/uploads/php/files/ece7366943d27ab11a29fdfd17c03606/93514159824.pdf
- http://geology.ie/wp-content/plugins/formcraft/file-upload/server/content/files/160f613f08b043---64797312533.pdf
- http://skikk.nl/app/webroot/files/userfiles/files/17668790613.pdf
- https://carcable-bg.com/uploads/pictures/files/soronuri.pdf
- http://holycrossyouthministryasp.org/clients/f/fa/fa15eac34f6f8ef5a8ada011ffef1578/File/74123982348.pdf
- https://provisionsinternational.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606d55999f46e---80692960446.pdf
- http://erkerlaender.de/wp-content/plugins/formcraft/file-upload/server/content/files/160b555bd1601d---45201709272.pdf
- http://rts-3.ru/upload/files/24414689831.pdf
- http://train-in-japan.com/images/blog//file/84018391607.pdf
- https://seataclightingalaska.com/wp-content/plugins/super-forms/uploads/php/files/94b847afa4cb4f00dc752c5635897b11/moxewerina.pdf
- https://suhrsmad.dk/wp-content/plugins/formcraft/file-upload/server/content/files/160ae14f46dd14---suziwaw.pdf
- http://doublehappyvstheinfinitesadness.com/wp-content/plugins/formcraft/file-upload/server/content/files/160943a5ef19e0---81343355384.pdf
- http://allamericannursing.com/userfiles/file/2766989192.pdf
- https://jamiatulbanat.in/wp-content/plugins/formcraft/file-upload/server/content/files/16086dfbd0eb93---vuvolotezedimapapevone.pdf
- http://cbwmd.com/uploads/Files/dapubewesowut.pdf
- https://willmarlakesarea2040.com/ckfinder/userfiles/files/3089709113.pdf
- https://dezsredstvompx.ru/wp-content/plugins/super-forms/uploads/php/files/402f78b0a63834928c21eb1e51d57e8b/96178484936.pdf
- https://www.onestopnaturalstore.ca/wp-content/plugins/super-forms/uploads/php/files/tcrll30frgc1j0jl8io5h1gbl4/fixomunojanu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- www.toptalentusa.com
- libertyquad72.fr
- colescastle.com
- edukiya.com
- skikk.nl
- carcable-bg.com
- holycrossyouthministryasp.org
- provisionsinternational.com
- erkerlaender.de
- rts-3.ru
- train-in-japan.com
- seataclightingalaska.com
- doublehappyvstheinfinitesadness.com
- allamericannursing.com
- jamiatulbanat.in
- cbwmd.com
- willmarlakesarea2040.com
- dezsredstvompx.ru
- www.onestopnaturalstore.ca
- www.w3.org
- purl.org
- ns.adobe.com
- vienkiemis.lt
- panda-es.tokyo
Embedded IP addresses
- 4.247.188.233
- 172.172.255.218
- 135.233.95.144
- 52.168.117.170
- 52.123.252.238
- 52.110.12.3
- 52.110.12.24
- 4.230.171.124
- 52.230.59.222
- 13.69.109.130
- 40.104.4.2
- 74.178.76.128
- 52.123.129.14
- 74.179.77.204
- 74.178.232.29
- 203.26.79.13
- 92.223.78.30
- 51.105.71.136
- 52.168.117.174
- 52.168.112.66
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report