MALICIOUS — dae103155ccc246b4d42f18fa419ae8fdca3f941d4d4c07ddcdfc3d6856d8856
MALICIOUS — dae103155ccc246b4d42f18fa419ae8fdca3f941d4d4c07ddcdfc3d6856d8856 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
dae103155ccc246b4d42f18fa419ae8fdca3f941d4d4c07ddcdfc3d6856d8856 - SHA-1:
514f844821886c6b31c3d7ef5f0faab88c5c9876 - MD5:
20cae11f98834db1f205fb816a48c7f6 - ssdeep:
1536:cr5Sov1LokKwkVQIAsbUlhJFdeGWkUvhf9fz/81C:+SovjkVpAsb8xNUvhf9fjf - TLSH:
T15C39E0B39283EDCC7687CB43EDD6185CA489C3D97423EAA14088BA5DC67C6BD3E14560 - Submitted as: dae103155ccc246b4d42f18fa419ae8fdca3f941d4d4c07ddcdfc3d6856d8856
- File type: pdf · Size: 85331 bytes
- Verdict: malicious (98/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!20CAE11F9883
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/2da8e9da-a54a-46f2-8fa0-495a170edf00/elite_3.2_qt_digital_air_fryer_reviews.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 16 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://dugedepap.ru/strik?utm_term=is+nessun+dorma+hard+to+sing, https://uploads.strikinglycdn.com/files/2da8e9da-a54a-46f2-8fa0-495a170edf00/elite_3.2_qt_digital_air_fryer_reviews.pdf, https://uploads.strikinglycdn.com/files/e08e376d-afc8-4f39-a0b9-1a451f80598e/1333977654.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9721 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9?P1=1787939752&P2=404&P3=2&P4=RRs1k3%2f%2fR4azH3AmHVjFCSfLUgH6RHnDtuxc1EgjHgucTOsV%2bRSSHqRApzFqHQ5K76D7Inbup%2f0T%2fzqGBq9v4g%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787939800&P2=404&P3=2&P4=XPLhk%2f7k5RbNS%2f9GqyCx48EQGS%2bk2Smr00GIgxQn4NKjlGXHdLPQYM06xwJsCH9MWOn6eukTbfWS0YKa7BdyWw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787336521&P2=404&P3=2&P4=dI6kizCpPNETk6Gfgq3qY%2bdq0cwrT2JElaZBZWG7aByivDzxxLm0mgBfkaE81k2uoWUcT6xQPImAab1D%2bqSqPA%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
2cc6194c33b2010ba1a5cbb7108451691bef7a02ff4b9fd1788578837e837537 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\df930cb08467985d89b238e7bacc4e19.png -
b20d401c0e29de3b3617dc88d550b859fc7d678cd0307f0f1d3d6de385f87fd6 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://dugedepap.ru/strik?utm_term=is+nessun+dorma+hard+to+sing
- https://uploads.strikinglycdn.com/files/2da8e9da-a54a-46f2-8fa0-495a170edf00/elite_3.2_qt_digital_air_fryer_reviews.pdf
- https://uploads.strikinglycdn.com/files/e08e376d-afc8-4f39-a0b9-1a451f80598e/1333977654.pdf
- https://uploads.strikinglycdn.com/files/3c8fa0f5-4153-45f6-b38c-84e3ab157fae/sheikh_mishary_rashid_alafasy_surah_mulk_mp3_download.pdf
- http://supsun-aero.com/28010437907k8l18.pdf
- https://s3.amazonaws.com/tarajix/wetixirasopojulomomi.pdf
- http://thelait.pro/32794444096sgz2w.pdf
- http://joxisuzu.rf.gd/silent_hunter_iii_commander.pdf
- http://varakeno.iblogger.org/article_35a_in_english.pdf
- http://maxirem.mygamesonline.org/how_to_interpret_biochemistry_results.pdf
- https://uploads.strikinglycdn.com/files/c6c937ea-805f-4798-bc53-a1c76e58ea30/awakened_house_of_night_free_download.pdf
- http://wupuwijekoja.rf.gd/arte_barocca.pdf
- http://kageditivumimor.onlinewebshop.net/13001039871.pdf
- http://duguferebijojo.rf.gd/jain_irrigation_annual_report_2018.pdf
- http://wepikupovug.myartsonline.com/lavumewafifinudetuz.pdf
- https://s3.amazonaws.com/bogijexu/what_types_of_chinese_food_are_gluten_free.pdf
- https://lefusavuforuv.weebly.com/uploads/1/3/4/4/134490278/miwaxi.pdf
- https://giwitororozesal.weebly.com/uploads/1/3/4/6/134652081/begomegan.pdf
- http://wei-nmvc.com/majimuzelotosewotek08y7.pdf
- http://onesmall.space/fancy_names_for_chocolate_dessertsr9ct9.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- dugedepap.ru
- uploads.strikinglycdn.com
- supsun-aero.com
- s3.amazonaws.com
- thelait.pro
- varakeno.iblogger.org
- maxirem.mygamesonline.org
- kageditivumimor.onlinewebshop.net
- wepikupovug.myartsonline.com
- lefusavuforuv.weebly.com
- giwitororozesal.weebly.com
- wei-nmvc.com
- onesmall.space
- www.w3.org
- purl.org
- ns.adobe.com
- joxisuzu.rf.gd
- wupuwijekoja.rf.gd
- duguferebijojo.rf.gd
Embedded IP addresses
- 104.208.16.94
- 57.155.104.224
- 52.110.12.14
- 4.144.132.114
- 4.230.171.124
- 72.154.7.96
- 203.26.79.13
- 51.105.71.136
- 74.179.77.204
- 52.123.129.14
- 135.234.160.244
- 135.233.95.80
- 52.168.117.171
- 172.175.111.170
- 4.207.44.68
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report