MALICIOUS — da0b4a0f6d21005d989538eb31bd2db1dcdb265a86366636cdde888255abc33a
MALICIOUS — da0b4a0f6d21005d989538eb31bd2db1dcdb265a86366636cdde888255abc33a is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
da0b4a0f6d21005d989538eb31bd2db1dcdb265a86366636cdde888255abc33a - SHA-1:
0351f473209fbf03a244a03712646ca10d2afc08 - MD5:
7030db64d25ce33509445cd7468e8cde - ssdeep:
1536:hrQvUsSGob4csiM6KgGocw4UoznGSW01GlqHSjW6pOu2aX/q8iklT:7GobeiygGT/jG21bSou2ai87 - TLSH:
T1B437CFF32197DC8CB75BDF47789711A891CED24820A2EAA181487B9CD8BC96E3F04840 - Submitted as: da0b4a0f6d21005d989538eb31bd2db1dcdb265a86366636cdde888255abc33a
- File type: pdf · Size: 70124 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 25 external host(s) at runtime (23 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: http://bjzjygj.com/fckeditor/editor/filemanager/connectors/php/userfiles/file/29141683314.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://synerhu.ru/uplcv?utm_term=redmi+note+9s+in+sri+lanka, https://serihosting.com/calisma2/files/uploads/72226486801.pdf, http://retco.ge/ckfinder/userfiles/files/mojebevibejoxukigu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
8615 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- settings-win.data.microsoft.com
- www.msn.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
1fd995083660605a1ff2b3b135be186886d3d1dab2f7257d080b1027b50b0a33 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\00fcc3b101338faa5064b3db7d77bc29.png -
500a8e0cd5dd2d5be9633f4f9c42847020ebc2947d74433eb4d3d1e7dd55efb0
Embedded URLs
- https://synerhu.ru/uplcv?utm_term=redmi+note+9s+in+sri+lanka
- https://serihosting.com/calisma2/files/uploads/72226486801.pdf
- http://retco.ge/ckfinder/userfiles/files/mojebevibejoxukigu.pdf
- http://bjzjygj.com/fckeditor/editor/filemanager/connectors/php/userfiles/file/29141683314.pdf
- http://tungalag.mn/userfiles/files/kuwegexupoxemab.pdf
- https://beldapin.com/calisma2/files/uploads/vutuworulovimu.pdf
- http://pxmonastery.org/CKEdit/upload/files/8430328109.pdf
- http://ranahytta.com/ckfinder/userfiles/files/sodilekalomaleta.pdf
- https://lrsinc.co/userfiles/file/majuxesuwefakujotajivu.pdf
- http://3e3i.com/UserFiles/file///metirutaguruniluzet.pdf
- http://dienvietbac.com/uploads/files/26154801265.pdf
- http://acril.ru/ufiles/files/sosel.pdf
- https://ferdavagnar.is/images/fck/file/39734406799.pdf
- https://www.vibrationmonitoring.asia/wp-content/plugins/formcraft/file-upload/server/content/files/1615213238cbf2---67095572848.pdf
- http://rebizplus.com/userfiles/file/vexefevezazapeto.pdf
- https://photofetimages.com/savilum.pdf
- http://tms-technology.com/ckfinder/userfiles/files/rejosamutelez.pdf
- http://safarang.com/basefile/files/tonegizijojisef.pdf
- https://ww150004.linebot.net/upfile/files/20210908210151.pdf
- http://identik.hu/editor_up/78997845218.pdf
- http://sanarina-coaching.de/ckfinder/userfiles/files/lezajikojagamajesek.pdf
- https://guptajimarriagebureau.com/userfiles/file/31779648554.pdf
- http://vistobrasil.net/uploads/file/gutuwasope.pdf
- https://eagleegg5k.com/ckfinder/triplebuserfiles/file/jeruzukomirilewa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- synerhu.ru
- serihosting.com
- bjzjygj.com
- beldapin.com
- pxmonastery.org
- ranahytta.com
- lrsinc.co
- 3e3i.com
- dienvietbac.com
- acril.ru
- www.vibrationmonitoring.asia
- rebizplus.com
- photofetimages.com
- tms-technology.com
- safarang.com
- ww150004.linebot.net
- sanarina-coaching.de
- guptajimarriagebureau.com
- vistobrasil.net
- eagleegg5k.com
- www.w3.org
- purl.org
- ns.adobe.com
- retco.ge
- tungalag.mn
Embedded IP addresses
- 20.165.94.46
- 52.168.117.174
- 52.123.252.248
- 20.247.184.197
- 85.210.193.152
- 4.230.171.124
- 172.215.188.232
- 52.123.252.245
- 135.232.92.137
- 74.178.76.54
- 4.207.44.73
- 20.76.201.171
- 172.66.2.5
- 52.123.129.14
- 52.123.128.14
- 203.26.79.13
- 135.233.45.223
- 52.123.252.212
- 135.233.95.80
- 52.148.114.188
- 72.154.7.101
- 172.175.111.170
- 172.178.240.162
- 52.110.12.30
- 52.110.12.31
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report