MALICIOUS — e0392352641300f1a2e941f34993f15755cfcd2e3672f272e4b52eba3c030d4f
MALICIOUS — e0392352641300f1a2e941f34993f15755cfcd2e3672f272e4b52eba3c030d4f is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e0392352641300f1a2e941f34993f15755cfcd2e3672f272e4b52eba3c030d4f - SHA-1:
dffdcd5f9296248994de9233560548831d120f14 - MD5:
7f7134ca0f1c994d628954196b27b32a - ssdeep:
1536:96zagKsb7sFn7XSridn/ft93rg1DHM9aW6pOu2VPrxJl/WJJRduS69hFL13:GpH7KrSrsf3r/Zu2V1JlCaS6VR - TLSH:
T14F38BFF3725BDD4C76469B036AF91168B085D7CC6032EAA051887B6DC5BC2FEBE04A11 - Submitted as: e0392352641300f1a2e941f34993f15755cfcd2e3672f272e4b52eba3c030d4f
- File type: pdf · Size: 82427 bytes
- Verdict: malicious (95/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 12 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://potlista.com/file/files/12101802482.pdf, https://aquaprosmart.com/userfiles/files/10046565275.pdf, https://igruppe.no/ckfinder/userfiles/files/sovujiboluwevaxufimefan.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9616 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787802359&P2=404&P3=2&P4=gJKRo84z7OA0BFU8XB64UQSOJcjm59oRiqF4QPkma2PJbRPLMyXaguUCXRegRFnR0ae50Yn4uVKzvs1pFTA3KA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787802444&P2=404&P3=2&P4=d5PtFb%2b%2bqGshrmcII2rChO9joRBrQW0tbHmvlA415SG1FBY5OFER4k5eLN5dZ%2bg12TZ%2f0LbBOcGByM6G3erTRQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- 23.40.52.209
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\6f00482dd73b8aec1995f2fefa5affe5.png -
22bb4116732ffcac01c76b28c57d3e7a11ba4ffb926b0ec9078082514e875e32 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
f5f76542ab253899ccead7b56f98632d91fea33fd067ffea1831e66f58333a39 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/DOqCt-cVA4I/uplcv?utm_term=the+vampire+diaries+book+2+read+online
- http://potlista.com/file/files/12101802482.pdf
- https://aquaprosmart.com/userfiles/files/10046565275.pdf
- https://igruppe.no/ckfinder/userfiles/files/sovujiboluwevaxufimefan.pdf
- https://isuzuphonoi.com/data/dulieu/files/muvupuxuruvukiboj.pdf
- http://aerotechgroup.ru/img/outer/files/rozev.pdf
- https://larioenergy.net/uploads/file/kereded.pdf
- http://www.southforconstruction.com/frontend/web/ckfinder/userfiles/files/parasexuwunam.pdf
- http://aktifithalat.com/resimlerfiles/12445745020.pdf
- http://3gr-group-com.gbintl.com/ci/userfiles/files/28539236744.pdf
- http://perechen-jurnalov.ru/js/ckfinder/userfiles/files/84697587367.pdf
- http://emilymillerlaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/jajujotamabesaboz.pdf
- https://mi-stores.com/basketballtotaal/images/editor/file/lemamevulowabuxopop.pdf
- https://gallerylingard.com/uploads/file/fenifibagudugose.pdf
- http://cokhivietuc.webthoidai.com/img-vietuc/files/20487671109.pdf
- http://maudchristan.nl/ckfinder/userfiles/files/mamadawomadefutevoni.pdf
- http://gucaoyun.com/uploads/file/060323436334.pdf
- http://aktasmatbaacilik.com/resimlerfiles/manalawasigapikoxu.pdf
- https://5of7edwardstreet.com/assets/media/files/32524842902.pdf
- https://phoenixknights.co.uk/wp-content/plugins/super-forms/uploads/php/files/89bf1086609cf0c2eb12e9fc55c375e3/81429814216.pdf
- http://changwontour.kr/FileData/ckfinder/files/20210903_6849D552DB3EF493.pdf
- http://rpsbchamber.org/editorData/file/xiwomuderukili.pdf
- http://atamergranit.com/userfiles/file/664182423.pdf
- https://bikidi.com/UpFiles/WebEditorFiles/file/49375498540.pdf
- http://nusratali.com/userfiles/files/64768554771.pdf
Embedded domains
- feedproxy.google.com
- potlista.com
- aquaprosmart.com
- igruppe.no
- isuzuphonoi.com
- aerotechgroup.ru
- larioenergy.net
- www.southforconstruction.com
- aktifithalat.com
- 3gr-group-com.gbintl.com
- perechen-jurnalov.ru
- emilymillerlaw.com
- mi-stores.com
- gallerylingard.com
- cokhivietuc.webthoidai.com
- maudchristan.nl
- gucaoyun.com
- aktasmatbaacilik.com
- 5of7edwardstreet.com
- phoenixknights.co.uk
- changwontour.kr
- rpsbchamber.org
- atamergranit.com
- bikidi.com
- nusratali.com
Embedded IP addresses
- 51.104.15.252
- 52.230.60.54
- 52.110.12.2
- 4.230.171.124
- 135.232.92.97
- 135.233.95.144
- 13.89.179.12
- 40.103.64.226
- 74.178.76.44
- 72.153.5.61
- 203.26.79.13
- 52.123.252.245
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report