MALICIOUS — e1a36882d91a9c0a9e62ef0c08272e1c8f20ab77543efe49fb479b8fb33d6abb
MALICIOUS — e1a36882d91a9c0a9e62ef0c08272e1c8f20ab77543efe49fb479b8fb33d6abb is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
e1a36882d91a9c0a9e62ef0c08272e1c8f20ab77543efe49fb479b8fb33d6abb - SHA-1:
4edd4e2a935f9e7c2b6eaed53a8022859606cb6c - MD5:
8e272a965bf14df6ab08d2a99a45fb11 - ssdeep:
1536:qATty6dRf7UCPOPLL8a9unlq7vxP4ftdw5+fLbkEZ7eWSrb/XEz8AWapOnrbl:nhyrCPODdmIq05+fsEZ7Mrb/XEAJn1 - TLSH:
T12A39D0F3209BDD9C764B8F43ADBA0128B44AE2885231DB908188B76CE97C57D7F41952 - Submitted as: e1a36882d91a9c0a9e62ef0c08272e1c8f20ab77543efe49fb479b8fb33d6abb
- File type: pdf · Size: 84328 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://g-shocktou.com/user_file/file/70063233663.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 19 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://maremio.ru/admin/ckfinder/userfiles/files/kefigazopotenifoxofosu.pdf, http://www.sunarmisir.com.tr/wp-content/plugins/super-forms/uploads/php/files/h2qt8r9t1bd180om99j6jj3tm0/63067578621.pdf, https://arhometutor.com/userfiles/file/fenagabonajudizo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9807 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
5410615ac076cd5cdf4d5d1afc5322137b62837636332c8d82388c154719e56a - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\06773901827f7b8995e922f3b78527b2.png -
ddceaa452372bb1a8aeaceda6f2c806d2e925eaefd6f24496c315ac01f8ddc52 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/BvfzZFkJO3s/uplcv?utm_term=german+picture+dictionary+pdf+free+download
- http://maremio.ru/admin/ckfinder/userfiles/files/kefigazopotenifoxofosu.pdf
- http://www.sunarmisir.com.tr/wp-content/plugins/super-forms/uploads/php/files/h2qt8r9t1bd180om99j6jj3tm0/63067578621.pdf
- https://arhometutor.com/userfiles/file/fenagabonajudizo.pdf
- http://g-shocktou.com/user_file/file/70063233663.pdf
- http://4bzsoftware.com/Images_upload/files/40973510094.pdf
- http://kwong-cheong.com/userfiles/73559101512.pdf
- http://anhuishangbiao.com/upload_fck/file/2021-5-2/20210502222304115597.pdf
- https://harpethvalleyhealth.com/wp-content/plugins/super-forms/uploads/php/files/aa880b4aec8c52df73de6286474b09b5/66742966802.pdf
- https://brianhigbielaw.com/UserFiles/file/40750844017.pdf
- http://www.psstrecno.sk/wp-content/plugins/formcraft/file-upload/server/content/files/160b1bbd98a1e0---xuvujetetexaludedobax.pdf
- https://wscnaturalhealings.com/wp-content/plugins/super-forms/uploads/php/files/65bd4b5963c16fc5dc275b421ffab9ec/61635604276.pdf
- http://x04ydivan.ru/userfiles/file/denotozoj.pdf
- https://aeap.com.br/ckfinder/userfiles/files/xixebibisimik.pdf
- https://asiatravel.kg/wp-content/plugins/super-forms/uploads/php/files/e1da2ff8337df2ad2bf2e0942542ae61/73023234222.pdf
- http://jnafarms.com/clients/864068/File/nixejo.pdf
- http://tv-sat.cz/userfiles/file/83429476612.pdf
- https://samiznojmo.cz/wp-content/plugins/super-forms/uploads/php/files/940e242d5e2331d206d63855cacc43dc/buwifuxedodujogom.pdf
- https://ratco-hardware.com/Ups/files/78623261048.pdf
- https://medok18.ru/wp-content/plugins/super-forms/uploads/php/files/01305c5f8cebbdfefc25d00e25fc400a/49055482667.pdf
- http://www.celso.org/download/37242374060.pdf
- https://40parables.com/wp-content/plugins/super-forms/uploads/php/files/3978ca58cfa7f1fd71f8ea3141cf4587/67018226869.pdf
- https://nazrabilisim.com/calisma2/files/uploads/vokeveneluruwolerojofu.pdf
- http://camonetinternational.com/files/file/gigarofarit.pdf
- http://www.ellisrasbetonwerke.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/1608ecef1a74e6---36533682853.pdf
Embedded domains
- feedproxy.google.com
- maremio.ru
- arhometutor.com
- g-shocktou.com
- 4bzsoftware.com
- kwong-cheong.com
- anhuishangbiao.com
- harpethvalleyhealth.com
- brianhigbielaw.com
- wscnaturalhealings.com
- x04ydivan.ru
- aeap.com.br
- jnafarms.com
- ratco-hardware.com
- medok18.ru
- www.celso.org
- 40parables.com
- nazrabilisim.com
- camonetinternational.com
- www.ellisrasbetonwerke.co.za
- thepetrichortouch.com
- dossalas.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 20.184.175.15
- 172.66.2.5
- 52.110.12.16
- 40.84.85.40
- 4.230.171.124
- 4.144.132.114
- 74.178.76.54
- 20.231.239.246
- 74.179.77.204
- 52.123.129.14
- 40.104.4.2
- 40.103.64.226
- 72.145.35.110
- 203.26.79.13
- 4.150.223.102
- 172.175.111.170
- 20.184.175.4
- 20.42.73.31
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report