MALICIOUS — b9e31873690bdf1806a093774c96175e1bd41852e1dfdcb73a1855f87eca67ea
MALICIOUS — b9e31873690bdf1806a093774c96175e1bd41852e1dfdcb73a1855f87eca67ea is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
b9e31873690bdf1806a093774c96175e1bd41852e1dfdcb73a1855f87eca67ea - SHA-1:
9dc57f6de20210b9245ebd4baaa3966e9b31bcc5 - MD5:
663763412f56e4e604f1a0ba125bbd17 - ssdeep:
1536:JcVV5k2Z0NZ4BXBp48nP/ddwtQ+XB3K6JD56O0WHBxRb0VW8pO76x6:EKNZ4tBp4+PDOrXBdD56OrBrb0U7t - TLSH:
T10237CFE331C7DD8CB78B8F036ABB10A9A44AD7D81131FA60558CBD6C953C67EAE50900 - Submitted as: b9e31873690bdf1806a093774c96175e1bd41852e1dfdcb73a1855f87eca67ea
- File type: pdf · Size: 74830 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://kaushalacademy.org/ckfinder/userfiles/files/medufikepefuviborodifi.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 16 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://infrive.ru/uplcv?utm_term=car+racing+3d+hack, http://ngocminhcnc.com/demo_thietbimay_24_7/upload/files/zexajejadajopuvujuzoxi.pdf, https://bandotrading.it/uploads/file/sekupidiparujobojidena.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9608 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787817990&P2=404&P3=2&P4=N191q5IZi05DnWu4pyq6nNgOKKN6jqPTvV%2fWAKVX6EUR4%2fhbrMsUySjDvPqnPdrWlummcL321f172m3O%2fTzGsQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\1c4cbf0b14a417c507468990cfce858f.png -
1e6daf8d6c1bc6b4eb59a48153296b8d15e41a27e60222c1289cd0d992d6c137 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
4a78acd42abb61b5e33886747b0e4b33badf785a67824ab7078f2f8e730708b5 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://infrive.ru/uplcv?utm_term=car+racing+3d+hack
- http://ngocminhcnc.com/demo_thietbimay_24_7/upload/files/zexajejadajopuvujuzoxi.pdf
- https://bandotrading.it/uploads/file/sekupidiparujobojidena.pdf
- http://kaushalacademy.org/ckfinder/userfiles/files/medufikepefuviborodifi.pdf
- http://meble-tk.pl/userfiles/file/vawixifu.pdf
- https://thuaphatlaihanoi.net/uploads/files/zesulivewipomugi.pdf
- https://hosvagyok.hu/userfiles/file/kunere.pdf
- http://studiotecnicostradi.eu/userfiles/files/nefefunujigided.pdf
- http://biomax.shop/filespath/files/20210920050319.pdf
- http://stl-hk.net/userfiles/rujixaxanas.pdf
- http://ndt-ultratech.com/files/69200858729.pdf
- https://war-old.its.vn/new/userfiles/file/mudose.pdf
- http://zbirozskepodzamci.cz/userfiles/34612526100.pdf
- http://yingtailong.com/upload/file/210920045959677131jye3dmevc121.pdf
- https://phukienbep.net/media/files/19438739457.pdf
- https://piataafacerilor.ro/app/webroot/files/userfiles/files/90550672823.pdf
- http://portaldeaquidauana.com.br/ckfinder/userfiles/files/82073826796.pdf
- http://lonerangerfanclub.com/ckfinder/userfiles/files/53367228111.pdf
- http://www.scea.edu.mn/ckfinder/userfiles/files/65187343412.pdf
- http://hidramaco.com/files/files/balupitedaluwob.pdf
- http://banner-ever.com/ckImg/files/72673532616.pdf
- https://demo.wsbe17hongkong.hk/_bin/ckfinder/userfiles/files/togidibosufag.pdf
- https://helicopterleasingservices.com/userfiles/files/guzebixomukalodibese.pdf
- http://sxnqx.org/upload/file/Fl202109091504202458.pdf
- http://delannahotel.com/user_img/file/sudozogasataxop.pdf
Embedded domains
- infrive.ru
- ngocminhcnc.com
- bandotrading.it
- kaushalacademy.org
- meble-tk.pl
- thuaphatlaihanoi.net
- studiotecnicostradi.eu
- biomax.shop
- stl-hk.net
- ndt-ultratech.com
- yingtailong.com
- phukienbep.net
- portaldeaquidauana.com.br
- lonerangerfanclub.com
- hidramaco.com
- banner-ever.com
- demo.wsbe17hongkong.hk
- helicopterleasingservices.com
- sxnqx.org
- delannahotel.com
- www.w3.org
- purl.org
- ns.adobe.com
- hosvagyok.hu
- war-old.its.vn
Embedded IP addresses
- 20.89.1.8
- 172.66.2.5
- 4.230.171.124
- 20.247.184.142
- 92.223.78.30
- 104.46.162.231
- 74.179.77.204
- 40.99.133.226
- 52.123.128.14
- 52.123.129.14
- 20.165.94.46
- 203.26.79.13
- 48.200.63.27
- 4.150.223.112
- 20.42.65.94
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report