MALICIOUS — 11619852744.pdf
MALICIOUS — 11619852744.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
dda96265dfcfe26d8cb394ec652b6165aea90784aa511360776ef1d34e094728 - SHA-1:
b0ca1a4109c12e3accbafc901a9e91c96081bb4a - MD5:
b58b9091aa3885649dd57dd730b48375 - ssdeep:
1536:wiVpLdGAXuyZqdSxK9IkuJbVO+kApf8LbqLlpcRWXFdoVlP3FeO:x7cyZqILbA7g8vqxKRYFdojZ - TLSH:
T12C38CFF36483CEDCBA928F03A9BA255E2589C78C6139DEC45488773CC4BC2BE6D61541 - Submitted as: 11619852744.pdf
- File type: pdf · Size: 82948 bytes
- Verdict: malicious (98/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!B58B9091AA38
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/2458e652-f5c1-4b5f-a8af-26640129a0b6/black_male_names_that_start_with_r.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 21 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://midufefew.ru/strik?utm_term=when+a+very+shy+guy+likes+you, https://tusukufuduma.weebly.com/uploads/1/3/4/4/134458322/9f18e384.pdf, https://cdn.sqhk.co/tifozeborot/ihig6jj/spotlight_x_room_escape_walkthrough_level_3.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (9 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9852 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- 252.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\175022ddb1f70e9d0fc526c330d90e9b.png -
5e0bde8f3ed6ec37ee47890da76811aac3fdd8fac7e5c5e5d08331a599430047 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
a4dc212114fbd1383b4ff926b7ffd19aaac8bb79814c06ea2fc3803e8d5d9cf5 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://midufefew.ru/strik?utm_term=when+a+very+shy+guy+likes+you
- https://tusukufuduma.weebly.com/uploads/1/3/4/4/134458322/9f18e384.pdf
- https://cdn.sqhk.co/tifozeborot/ihig6jj/spotlight_x_room_escape_walkthrough_level_3.pdf
- https://cdn.sqhk.co/dijabidasu/gIFHq1R/wawiva.pdf
- https://ginimowawogob.weebly.com/uploads/1/3/4/7/134753870/bejapibewusamen.pdf
- https://lusimijibujadex.weebly.com/uploads/1/3/4/6/134677052/mumekogoxozuweki.pdf
- https://sapilijufidukuw.weebly.com/uploads/1/3/4/9/134901451/1bd27d272ce06f.pdf
- https://s3.amazonaws.com/bajapovogam/4689222684.pdf
- https://s3.amazonaws.com/dumupa/caremark_prior_auth_form_for_adderall.pdf
- https://uploads.strikinglycdn.com/files/2458e652-f5c1-4b5f-a8af-26640129a0b6/black_male_names_that_start_with_r.pdf
- https://pafililesenuxag.weebly.com/uploads/1/3/5/9/135964876/9680286.pdf
- https://cdn.sqhk.co/pibexezases/fjbqAib/21160301487.pdf
- https://povemiloten.weebly.com/uploads/1/3/4/6/134608376/140e0bac003ce75.pdf
- https://cdn.sqhk.co/nizufalagef/gcmJhdp/64511389116.pdf
- https://s3.amazonaws.com/vifusupegiza/reelfoot_lake_fishing_guide_service.pdf
- http://tejasatobes.medianewsonline.com/beginning_signs_of_rheumatoid_arthritis_in_hands.pdf
- https://lemefiware.weebly.com/uploads/1/3/4/0/134017231/0072f9d66419e.pdf
- https://uploads.strikinglycdn.com/files/d8ccb14a-56e5-459e-8633-2ad2d9f59752/2nd_grade_math_worksheets_addition_and_subtraction.pdf
- https://gofubemasuxa.weebly.com/uploads/1/3/2/7/132712405/wibefipem_dibemawoxazek_xagadukifoxo.pdf
- http://gubadif.myartsonline.com/73692661867.pdf
- https://devubavoxonor.weebly.com/uploads/1/3/2/7/132741482/vobawumufe.pdf
- https://cdn.sqhk.co/zanuvajebodu/jdNgihg/15028518935.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- midufefew.ru
- tusukufuduma.weebly.com
- cdn.sqhk.co
- ginimowawogob.weebly.com
- lusimijibujadex.weebly.com
- sapilijufidukuw.weebly.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- pafililesenuxag.weebly.com
- povemiloten.weebly.com
- tejasatobes.medianewsonline.com
- lemefiware.weebly.com
- gofubemasuxa.weebly.com
- gubadif.myartsonline.com
- devubavoxonor.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 20.184.175.19
- 172.215.188.232
- 172.172.255.217
- 72.154.7.113
- 52.168.117.168
- 20.247.184.142
- 52.110.12.19
- 52.110.12.26
- 4.247.188.233
- 4.230.171.124
- 135.232.92.97
- 20.236.44.162
- 20.165.94.63
- 40.99.134.18
- 72.154.7.102
- 203.26.79.13
- 40.84.85.40
- 74.179.71.159
- 20.42.65.89
- 52.168.117.169
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report