MALICIOUS — e12aac1cf1b43dfca2285fdcaed3a5e2b6fadce0a682e537c6dd1cbd2478f793
MALICIOUS — e12aac1cf1b43dfca2285fdcaed3a5e2b6fadce0a682e537c6dd1cbd2478f793 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
e12aac1cf1b43dfca2285fdcaed3a5e2b6fadce0a682e537c6dd1cbd2478f793 - SHA-1:
46e88f15965e960975e8d1b8d0219acca0e9fd9a - MD5:
04f67edb6b72a06e3b35d22dd0b44cf4 - ssdeep:
1536:bNIOJhMcs/MMVChUGllZkEm7tyjllBff7yLJTGGAKUMOd3jIBeYD+Pg7BSNqHQUB:rJTMVcUGZkEmhypHH7nKUrd3jIYYD+4T - TLSH:
T12738C0F320D7DD9C76479B93EEA62B5DA04EC7842232C75014896B2CD8BC6BD3E00955 - Submitted as: e12aac1cf1b43dfca2285fdcaed3a5e2b6fadce0a682e537c6dd1cbd2478f793
- File type: pdf · Size: 82406 bytes
- Verdict: malicious (98/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!04F67EDB6B72
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/c546fcf3-bcfb-4db2-869f-a13c1e7bd077/59488824917.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 18 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://wastran.ru/pbw?utm_term=how+to+get+a+voice+modifier+on+xbox+one, https://uploads.strikinglycdn.com/files/c546fcf3-bcfb-4db2-869f-a13c1e7bd077/59488824917.pdf, https://lifigosup.weebly.com/uploads/1/3/4/8/134884960/sewafabakuronapifu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (7 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9716 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787804450&P2=404&P3=2&P4=IfGbB1S0arbHTWsdSv90LA9pIo4N2IGQKqj5h40xSYzRJIkcAc6Ag%2fVNYCVEeCBvbTRim2C%2fRci4RFrd5CyJtA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787804475&P2=404&P3=2&P4=h9RVuOm9KQo7tI2LImCIMTn5mx4Ea2y9q7aeIfVpKEOmH%2fSrvt3cjPcEVstapFTinla1ew9isGGCE3wpeorMVw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
856bfe61b777eaa7e6bebd1659658bb376e4cdcf8f55475a93bedaa35ea0cb0e - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\62ec76a5c823c5d81e156b6fa7ee1856.png -
f75f8d523580d578bfdf1b1dc951be5be48f9fa18314a016bec9ff14a5c96cdb - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://wastran.ru/pbw?utm_term=how+to+get+a+voice+modifier+on+xbox+one
- https://uploads.strikinglycdn.com/files/c546fcf3-bcfb-4db2-869f-a13c1e7bd077/59488824917.pdf
- https://lifigosup.weebly.com/uploads/1/3/4/8/134884960/sewafabakuronapifu.pdf
- https://zujakeme.weebly.com/uploads/1/3/4/0/134041616/7435046.pdf
- https://devoloxavigu.weebly.com/uploads/1/3/5/3/135318297/e110fd9a9e09.pdf
- https://jikudirag.weebly.com/uploads/1/3/4/0/134040407/zalivedabelisu.pdf
- https://kakizizutubune.weebly.com/uploads/1/3/4/3/134351089/retaxipebugakezawivo.pdf
- https://uploads.strikinglycdn.com/files/e568b0a9-bd89-4610-8504-489dd40a7536/ruwuvaxekaj.pdf
- http://kigiputilik.pbworks.com/w/file/fetch/144679779/kijetozukiwi.pdf
- https://xozowozorero.weebly.com/uploads/1/3/2/6/132695390/mirawekafopow.pdf
- https://uploads.strikinglycdn.com/files/6701892b-f7ee-480d-aee8-fc2791030ec7/dearborn_heater_grates.pdf
- https://puvemeximaz.weebly.com/uploads/1/3/4/4/134442093/foganuxavi-jubavik-segutoloxaris-vigovunu.pdf
- http://jolowajuwijo.pbworks.com/w/file/fetch/144588810/farming_simulator_18_unlimited_money_apk_obb.pdf
- https://zakelesi.weebly.com/uploads/1/3/7/5/137503615/5696640.pdf
- https://puzuzabijil.weebly.com/uploads/1/3/2/8/132814257/zazoxozudeme.pdf
- http://garewewaziwu.pbworks.com/f/deed_of_absolute_sale_vehicle_template.pdf
- https://waxojokizubow.weebly.com/uploads/1/3/4/4/134482073/2672058.pdf
- https://mabaxezo.weebly.com/uploads/1/3/4/7/134766945/wigobusita.pdf
- https://ruvezidarumova.weebly.com/uploads/1/3/1/3/131380493/8046c6.pdf
- https://gefipozaxafuni.weebly.com/uploads/1/3/5/3/135312829/koretejalojasop.pdf
- https://uploads.strikinglycdn.com/files/337a6db8-0671-430d-8ee0-e0a602cd4d3d/scotts_turf_builder_edgeguard_mini_broadcast_spreader_settings.pdf
- https://xewiriwi.weebly.com/uploads/1/3/4/6/134645045/sabifuwejejul-redowiro-julotoso.pdf
- https://uploads.strikinglycdn.com/files/79f16b46-9b05-4b38-8df6-69047120bc22/lord_of_the_rings_4k_steelbook_hmv.pdf
- https://linonorimezolup.weebly.com/uploads/1/3/7/5/137519838/1171354.pdf
- http://wejojixi.pbworks.com/f/man_of_the_house_veronica_gym_fight.pdf
Embedded domains
- wastran.ru
- uploads.strikinglycdn.com
- lifigosup.weebly.com
- zujakeme.weebly.com
- devoloxavigu.weebly.com
- jikudirag.weebly.com
- kakizizutubune.weebly.com
- kigiputilik.pbworks.com
- xozowozorero.weebly.com
- puvemeximaz.weebly.com
- jolowajuwijo.pbworks.com
- zakelesi.weebly.com
- puzuzabijil.weebly.com
- garewewaziwu.pbworks.com
- waxojokizubow.weebly.com
- mabaxezo.weebly.com
- ruvezidarumova.weebly.com
- gefipozaxafuni.weebly.com
- xewiriwi.weebly.com
- linonorimezolup.weebly.com
- wejojixi.pbworks.com
- dotofufodil.weebly.com
- xulisonifob.weebly.com
- nojarotawufa.weebly.com
- star-trek-voyager.net
Embedded IP addresses
- 52.123.252.223
- 162.159.142.9
- 52.123.252.204
- 135.232.92.34
- 52.110.12.44
- 4.230.171.124
- 203.26.79.13
- 20.42.65.94
- 74.179.77.204
- 52.123.128.14
- 51.105.71.137
- 52.123.252.224
- 74.178.240.61
- 52.168.117.169
- 52.123.252.226
- 92.223.78.30
- 4.207.44.68
- 172.170.180.133
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report