MALICIOUS — d1b3da7b3d3459776208fd0c12125a8100da635851146cba257eca67fb6fbc6f
MALICIOUS — d1b3da7b3d3459776208fd0c12125a8100da635851146cba257eca67fb6fbc6f is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
d1b3da7b3d3459776208fd0c12125a8100da635851146cba257eca67fb6fbc6f - SHA-1:
ceebaffe1735ade212739c0f721ce0fd93a1c8c1 - MD5:
7543001fffaf1854e7e7617720b96837 - ssdeep:
1536:j9Qev3SBd2O+nRVJGr+BNgGaXfqx8iMXT/De2qnmXFZ8d/3UzKmsARqNK84:ZQevGU7RDy+NgGiSLMXT7e2mrUKQR - TLSH:
T11537CFF361A7ED4C7A8BAB477AB71129748DD2486033D754208CB76C997C2AC3F24A50 - Submitted as: d1b3da7b3d3459776208fd0c12125a8100da635851146cba257eca67fb6fbc6f
- File type: pdf · Size: 75059 bytes
- Verdict: malicious (98/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!7543001FFFAF
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/a650d5e4-f913-4c4e-ada8-f30f556a9701/52493655350.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 14 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://infrive.ru/pbw?utm_term=blocs+wave+android, https://bomovote.weebly.com/uploads/1/3/5/3/135398027/4803271.pdf, https://xadixifiv.weebly.com/uploads/1/3/4/8/134888816/rilosovigepizoj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (13 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9643 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
e8607aa98b373eab61db8b8872fc6c3f4035e8a5a611ceb9b87d052308e11668 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\5ef0d88be8ee1d581aaa4db042ef15aa.png -
36768092a4262528235076dd43206a6203129c9fbbdd07949efb0e7b0d608d7d - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://infrive.ru/pbw?utm_term=blocs+wave+android
- https://bomovote.weebly.com/uploads/1/3/5/3/135398027/4803271.pdf
- https://xadixifiv.weebly.com/uploads/1/3/4/8/134888816/rilosovigepizoj.pdf
- https://femadupimasimu.weebly.com/uploads/1/3/4/5/134594559/2f31e.pdf
- https://xelavizagak.weebly.com/uploads/1/3/5/3/135325118/tuwig-nejuvas.pdf
- http://gabumur.pbworks.com/f/fortnite_tracker_stats.pdf
- https://static.s123-cdn-static.com/uploads/4482027/normal_5ff28643cdc9c.pdf
- https://tegikalom.weebly.com/uploads/1/3/0/8/130874380/welixewabeb.pdf
- https://uploads.strikinglycdn.com/files/a650d5e4-f913-4c4e-ada8-f30f556a9701/52493655350.pdf
- http://kigiputilik.pbworks.com/w/file/fetch/144678558/html_programming_tutorial.pdf
- https://uploads.strikinglycdn.com/files/878d40df-1922-46f5-ab49-963c3047452e/windows_7_arabic_language_pack_download_offline.pdf
- https://negalunuz.weebly.com/uploads/1/3/4/7/134702004/5454099.pdf
- https://uploads.strikinglycdn.com/files/3ddff60c-a9b4-4fb4-9e24-1657cf88f556/how_to_become_a_pr_professional.pdf
- https://cdn-cms.f-static.net/uploads/4452862/normal_602cf2ec25c43.pdf
- http://kukepofarit.pbworks.com/w/file/fetch/145107837/16_line_quran_with_color_tajweed_download.pdf
- https://cdn-cms.f-static.net/uploads/4447434/normal_60217e6749640.pdf
- http://likanegi.pbworks.com/w/file/fetch/144501873/fijig.pdf
- https://kirurivujet.weebly.com/uploads/1/3/1/4/131437430/toteberonezulal_kixaka_suwapegegudepo.pdf
- https://uploads.strikinglycdn.com/files/7137789f-e467-4c0b-85b8-795ba5c198b6/norton_anthology_of_american_literature_table_of_contents.pdf
- https://static.s123-cdn-static.com/uploads/4422137/normal_5fc80af14584a.pdf
- http://vamafob.pbworks.com/w/file/fetch/144662946/1156000354.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- infrive.ru
- bomovote.weebly.com
- xadixifiv.weebly.com
- femadupimasimu.weebly.com
- xelavizagak.weebly.com
- gabumur.pbworks.com
- static.s123-cdn-static.com
- tegikalom.weebly.com
- uploads.strikinglycdn.com
- kigiputilik.pbworks.com
- negalunuz.weebly.com
- cdn-cms.f-static.net
- kukepofarit.pbworks.com
- likanegi.pbworks.com
- kirurivujet.weebly.com
- vamafob.pbworks.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.110.12.24
- 52.110.12.52
- 4.247.188.224
- 4.230.171.124
- 52.253.84.76
- 74.178.240.61
- 4.150.223.114
- 135.232.92.97
- 52.123.128.14
- 52.123.252.241
- 72.154.7.103
- 203.26.79.13
- 52.123.252.216
- 20.42.65.89
File paths
- L:\`.
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report