MALICIOUS — bdef5c9cac0835f50821a32296f35093046e5b77865220bfef385116936fa2c9
MALICIOUS — bdef5c9cac0835f50821a32296f35093046e5b77865220bfef385116936fa2c9 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
bdef5c9cac0835f50821a32296f35093046e5b77865220bfef385116936fa2c9 - SHA-1:
e6718df1aca108f2d515ac6f41741a7d32e069a5 - MD5:
d5f003216eed8f91aa81d8e1df846567 - ssdeep:
1536:a5E7P+IXF8SuBIJTbwuwifGo14wLyyW+Os5OOYUgtv984Ek5380Ehp:z7maaBIaure2WQ5NgP84EU380Q - TLSH:
T12E39BFB720C7EE8DBA8B6F1369F721687049C3885172D78141887B7DD1BC2AD6F20A51 - Submitted as: bdef5c9cac0835f50821a32296f35093046e5b77865220bfef385116936fa2c9
- File type: pdf · Size: 87664 bytes
- Verdict: malicious (98/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!D5F003216EED
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4413236/normal_5fc91c55394b0.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 14 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://seumenha.ru/award?keyword=biochemistry+and+molecular+biology+elliott+5th+edition+pdf, http://btsworld.org/best_small_gps_tracking_devices3efgd.pdf, https://sivoroxusakigob.weebly.com/uploads/1/3/1/4/131453081/9b1fa9acd.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9840 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\6e12169ea4aa22b8992a8c3d54f4bb3e.png -
4befba41611509378062e34ef70d6216ff39ab50312491a1f1c2ac9b3aa1c282 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
ff1bedc09b9656b0dcad76c5ceeb5b2d58c47a00c5714f660849899c384c230e - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://seumenha.ru/award?keyword=biochemistry+and+molecular+biology+elliott+5th+edition+pdf
- http://btsworld.org/best_small_gps_tracking_devices3efgd.pdf
- https://sivoroxusakigob.weebly.com/uploads/1/3/1/4/131453081/9b1fa9acd.pdf
- https://static.s123-cdn-static.com/uploads/4413236/normal_5fc91c55394b0.pdf
- https://3e3188f7-d9e9-48da-9af6-4e6760718ee0.filesusr.com/ugd/4f7562_99a790a298be4f2dab87b5b236ec54a3.pdf?index=true
- https://cdn.sqhk.co/kinanekoxo/rhggdlo/popuwatujuw.pdf
- https://cdn.sqhk.co/pabelewexo/vgdhtgc/jalotowoga.pdf
- https://cdn.sqhk.co/navimoxa/hagfrib/perplexus_epic_3d_maze.pdf
- https://aa5f33e9-793b-4807-a257-9eac84d314d0.filesusr.com/ugd/aa57b2_36d052c7191845659ec011ff126dce75.pdf?index=true
- https://uploads.strikinglycdn.com/files/b77968ce-b86b-479f-b219-5b71226b617b/ropibefepuzusanidif.pdf
- https://uploads.strikinglycdn.com/files/f671909d-e46e-4374-b0b6-faded9ea6420/mirimilozi.pdf
- https://52a72965-a6d2-471e-b66a-59a59a4d663b.filesusr.com/ugd/e643da_92ce93be685f40689cce2af1268d3b01.pdf?index=true
- http://zoomita.fun/jekezigakobulofovisabaw2sw1i.pdf
- https://cdn-cms.f-static.net/uploads/4406191/normal_605967c0def34.pdf
- https://uploads.strikinglycdn.com/files/3db4832c-150e-47d8-98fa-6b0ce68b48f6/formulas_para_calcular_el_volumen_de_diferentes_figuras_geometricas.pdf
- https://zovakobazala.weebly.com/uploads/1/3/1/4/131456363/vutufiwoxurovaxunami.pdf
- https://cdn-cms.f-static.net/uploads/4501484/normal_600e86ad22a0b.pdf
- http://kukushpa.fun/capitals_and_currencies_of_all_countriesy7c2x.pdf
- https://17500468-634e-4f48-81ad-48a4a068d6fa.filesusr.com/ugd/dcac76_656d8aa27e724f808f6d1d3bb4774316.pdf?index=true
- http://douchehq.xyz/5762313065251gp3.pdf
- https://cdn.sqhk.co/zukasedu/gjKCkGK/3d_car_driving_simulator_games_online.pdf
- https://cdn.sqhk.co/tamejenonisi/dygjjgP/guwelagefanonavavat.pdf
- https://63b1f34b-4847-450f-8d9a-4788d10e1cf5.filesusr.com/ugd/451a43_edd797f3142c4be5ae01cc921b92efb9.pdf?index=true
- https://xekukagakodepa.weebly.com/uploads/1/3/3/9/133999272/vixorusiraxejibelo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- seumenha.ru
- btsworld.org
- sivoroxusakigob.weebly.com
- static.s123-cdn-static.com
- 3e3188f7-d9e9-48da-9af6-4e6760718ee0.filesusr.com
- cdn.sqhk.co
- aa5f33e9-793b-4807-a257-9eac84d314d0.filesusr.com
- uploads.strikinglycdn.com
- 52a72965-a6d2-471e-b66a-59a59a4d663b.filesusr.com
- zoomita.fun
- cdn-cms.f-static.net
- zovakobazala.weebly.com
- kukushpa.fun
- 17500468-634e-4f48-81ad-48a4a068d6fa.filesusr.com
- douchehq.xyz
- 63b1f34b-4847-450f-8d9a-4788d10e1cf5.filesusr.com
- xekukagakodepa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 4.150.223.110
- 172.66.2.5
- 52.123.252.195
- 85.210.193.152
- 4.230.171.124
- 20.165.94.63
- 92.223.78.30
- 74.178.76.54
- 74.179.77.204
- 203.26.79.13
- 52.123.128.14
- 40.103.64.242
- 4.209.250.170
- 13.89.179.15
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report