MALICIOUS — bdbfc4ad3d0aa397a3c5181c520b6fe06ac3d085bb9d94eee76b27f0a0c6c404
MALICIOUS — bdbfc4ad3d0aa397a3c5181c520b6fe06ac3d085bb9d94eee76b27f0a0c6c404 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
bdbfc4ad3d0aa397a3c5181c520b6fe06ac3d085bb9d94eee76b27f0a0c6c404 - SHA-1:
dd07c6644125b1ab035fdc47971a1cd54622f5ff - MD5:
0db34b566f0f8cfe523b93e3bec66fbb - ssdeep:
3072:KC7PmzAJYvC6D+73ey14wvSBRu+a1IbtSxm:9uvpD+73h4wKBod1IZ - TLSH:
T1D53CE1F3A067DD9C3ACAFBD369A6214D754DC25C22266A5410887A2DC8BC7BE3F10D50 - Submitted as: bdbfc4ad3d0aa397a3c5181c520b6fe06ac3d085bb9d94eee76b27f0a0c6c404
- File type: pdf · Size: 121404 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/c2a245e6-0cf3-43ff-9ad2-9ce5402344cd/how_much_oxygen_can_a_venturi_mask_deliver.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 17 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://mezovuduw.ru/wb?keyword=how%20much%20does%20a%20porsche%20928%20cost, http://everydayy.fun/mezcla_frigorifica_explicacion3ls4q.pdf, https://4328a374-8b5c-4134-9cef-e132ca5fc89d.filesusr.com/ugd/6732b1_f60b41f01e27432ab70cf49c18e5fec6.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9800 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- _dosvc._tcp.local
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
1b18de11fea836ee5e6f3cfa1a2ea0ad1de75390cdb34d28e74d5a96e11d9715 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\d64264944a0c7dcc3645e2d5dd48b5ca.png -
f57f90a46f9005a48bd09a3ad72c63a758a5a80cdedb6c6ff0ab0c36c0add9ae - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://mezovuduw.ru/wb?keyword=how%20much%20does%20a%20porsche%20928%20cost
- http://everydayy.fun/mezcla_frigorifica_explicacion3ls4q.pdf
- https://4328a374-8b5c-4134-9cef-e132ca5fc89d.filesusr.com/ugd/6732b1_f60b41f01e27432ab70cf49c18e5fec6.pdf?index=true
- https://uploads.strikinglycdn.com/files/c2a245e6-0cf3-43ff-9ad2-9ce5402344cd/how_much_oxygen_can_a_venturi_mask_deliver.pdf
- http://eduha.online/google_books_to_converterfwgl2.pdf
- https://00407fa8-a9ef-4b78-9bbe-46147fc8acf6.filesusr.com/ugd/5ecadc_d96a5e9c47bc4650afe0697711e4c824.pdf?index=true
- https://cdn.sqhk.co/mukibusu/jwUFgiY/nicki_minaj_songs_2020.pdf
- https://uploads.strikinglycdn.com/files/9645e166-578f-4355-83b7-e5a6f2fe923b/87876727758.pdf
- https://uploads.strikinglycdn.com/files/27de7f88-6e6a-4760-bdba-36c1655a9879/27236476240.pdf
- http://itanah.space/best_investment_for_2021_uk4v7fk.pdf
- https://uploads.strikinglycdn.com/files/61e6b5b6-d3c9-40dd-91be-c86c8582deaa/juwizojalaveba.pdf
- https://77bac38d-831a-46d6-8f22-d7743fcadc58.filesusr.com/ugd/5b9a87_5fd5b618c46446aab1a878030671305c.pdf?index=true
- https://uploads.strikinglycdn.com/files/a11e5db3-11e1-4da6-801e-73f176cde25c/bissell_proheat_12_amps_troubleshooting.pdf
- https://uploads.strikinglycdn.com/files/84a2fd96-18fd-474a-81c2-9a6ea11beb12/7611993816.pdf
- https://cdn.sqhk.co/zovaratigu/a8jjhcG/maze_runner_2_full_movie_download.pdf
- https://cdn.sqhk.co/josurowelimu/niaQGhd/53257948041.pdf
- https://uploads.strikinglycdn.com/files/fbfe1e19-fa60-4083-a459-f5b685424da0/how_many_calories_in_a_plate_from_panda_express.pdf
- http://boothattendant.com/asm_fmcg_biharhfp3g.pdf
- http://organicnu.info/tcl_roku_tv_50_inche7xij.pdf
- https://0ecef3a8-5193-4df1-8dcb-1b7dd0f2be2a.filesusr.com/ugd/e6092c_fdf74905412d435cae06e2eb9ee2a3cd.pdf?index=true
- https://uploads.strikinglycdn.com/files/5e441443-707b-4daa-b2ce-e4df61b63fc0/66160571165.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- mezovuduw.ru
- everydayy.fun
- 4328a374-8b5c-4134-9cef-e132ca5fc89d.filesusr.com
- uploads.strikinglycdn.com
- eduha.online
- 00407fa8-a9ef-4b78-9bbe-46147fc8acf6.filesusr.com
- cdn.sqhk.co
- itanah.space
- 77bac38d-831a-46d6-8f22-d7743fcadc58.filesusr.com
- boothattendant.com
- organicnu.info
- 0ecef3a8-5193-4df1-8dcb-1b7dd0f2be2a.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.168.117.174
- 74.179.77.204
- 4.144.132.223
- 52.110.12.55
- 4.230.171.124
- 40.84.97.4
- 20.165.94.63
- 74.178.240.51
- 20.231.239.246
- 40.103.64.242
- 52.123.129.14
- 135.234.160.247
- 135.233.95.80
- 203.26.79.13
- 20.42.72.131
- 48.192.143.121
- 20.42.65.85
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report