MALICIOUS — 96328497105.pdf
MALICIOUS — 96328497105.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e259c41e216854d8def91e4fd3d31d2db0aaecf0ca9104134cab9b0d03309663 - SHA-1:
ab42dc86b2fb1714be65ffa56c3f5f9a5f44a758 - MD5:
4e05a90ee9c5e8a73a3db4a9e0a9a2b8 - ssdeep:
1536:3Dd4IrFgum9Nx2m5id6Ev/sbqSvb9b7gi0rfWHm8oY0VAOhaWv/IT4LUycAWspO2:mIBKyJUbHb9b7gDK/0RhNzsr2Os - TLSH:
T1F739D0F36087DD6CB74B9B03ACAB156DA98AD7886233EA504188F61CD47C9BC7F10950 - Submitted as: 96328497105.pdf
- File type: pdf · Size: 87059 bytes
- Verdict: malicious (95/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 15 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://verkaufs-akademie.com/userfiles/file/33251828869.pdf, https://communeouchamps.fr/userfiles/file/91477462415.pdf, https://cristiandellavedova.com/wp-content/plugins/super-forms/uploads/php/files/b27dd64jn91jq8bhfqqklc58l1/gubizanivurumameb.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9789 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep._dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787779046&P2=404&P3=2&P4=JAchQ0ZV58YnUtkilCk9MsdbbWybpjht4LCoE9FOYCub8v9lGHLzFGp6NWF2XmPOWJA5cV3pHOf7B%2fCrkWpVhw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787779095&P2=404&P3=2&P4=TUFlwn8CkN2%2f%2fUrdkPfWvspjO4nuhiHMnc1eGlTDnZJbJ7cx5zJaVJhS24JtnLY4oCdkNm96L8sFU2WdDsXU0w%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\c8f797b9c6d2db48c3da07d99e4bbbcb.png -
f85a3aef974c395bd06eac653133497154f16d3370c43e59b1f681a0836e9832 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
675d307d704e2f6dcec219662460947208990275c88308460cbd20d9131a2e16 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/BvfzZFkJO3s/uplcv?utm_term=napco+gemini+1664+user+manual
- http://verkaufs-akademie.com/userfiles/file/33251828869.pdf
- https://communeouchamps.fr/userfiles/file/91477462415.pdf
- https://cristiandellavedova.com/wp-content/plugins/super-forms/uploads/php/files/b27dd64jn91jq8bhfqqklc58l1/gubizanivurumameb.pdf
- http://nwatchonline.net/userfiles/file/zefig.pdf
- https://fourseasons.events/wp-content/plugins/super-forms/uploads/php/files/1990ebe4c7092902d6f5837b09b2a32d/bukal.pdf
- http://www.adanakursmerkezi.com/wp-content/plugins/formcraft/file-upload/server/content/files/16104a34e0bfdc---jaxedasapo.pdf
- https://study-go.info/wp-content/plugins/super-forms/uploads/php/files/6a5a3b8e221d4f9b5fe73742e792202a/pugiruguxumupexepul.pdf
- https://upchealth.net/wp-content/plugins/super-forms/uploads/php/files/87c0d53fd2e9ed285ea655f5e9aed178/fetixukelevivujanipabutu.pdf
- https://www.expoagrogto.com/wp-content/plugins/super-forms/uploads/php/files/asb4ldfuu9gvb7u95ri7t63ip2/ziwovonele.pdf
- http://www.canadiantreasurer.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a648d6e2834---lubegifasetukogakep.pdf
- http://aiswaryamatrimonials.com/fck_uploads/file/43745944476.pdf
- http://titusrelay.com/clients/e/ef/ef304ccc03541e9e6382bef5f13b0a7d/File/savesupetetejazefagijo.pdf
- http://libron.pl/fckupload/assets/file/79911552801.pdf
- https://daxitrip.com/basefile/daxitripcom/files/mokirivaropukupaj.pdf
- http://ferramentabelleggia.it/public/file/63250828675.pdf
- https://sevsport.info/wp-content/plugins/super-forms/uploads/php/files/423176f6239302204e0dfbed565d897d/jukewazifumadexitofolopi.pdf
- https://aquarell.ro/userfiles/file/pozifaxumuzuzit.pdf
- http://escolacaritas.com/wp-content/plugins/formcraft/file-upload/server/content/files/160fd50b47654d---80831856196.pdf
- http://jeyadhurgatemple.com/userfiles/file/watasavaredojimolopef.pdf
- https://spencershaulageltd.co.uk/wp-content/plugins/super-forms/uploads/php/files/8f14add9d8a5871c0b05c2e82ce4a480/73808118454.pdf
- https://ibeguiristain.com/userfiles/files/67281984151.pdf
- https://www.lorenzofranzone.it/wp-content/plugins/super-forms/uploads/php/files/116e7f8d61930f33e3b24f1deaf95883/89332230720.pdf
- https://stef-nancy.fr/upload/document/3841829907.pdf
- https://amartzon.store/wp-content/plugins/super-forms/uploads/php/files/4e6bda8af0fd8cd1a0bbadddc097751a/suretagodagusax.pdf
Embedded domains
- feedproxy.google.com
- verkaufs-akademie.com
- communeouchamps.fr
- cristiandellavedova.com
- nwatchonline.net
- www.adanakursmerkezi.com
- study-go.info
- upchealth.net
- www.expoagrogto.com
- www.canadiantreasurer.com
- aiswaryamatrimonials.com
- titusrelay.com
- libron.pl
- daxitrip.com
- ferramentabelleggia.it
- sevsport.info
- escolacaritas.com
- jeyadhurgatemple.com
- spencershaulageltd.co.uk
- ibeguiristain.com
- www.lorenzofranzone.it
- stef-nancy.fr
- amartzon.store
- www.w3.org
- purl.org
Embedded IP addresses
- 4.150.223.106
- 4.144.132.223
- 52.123.252.194
- 52.110.12.33
- 4.247.188.224
- 4.230.171.124
- 162.159.142.9
- 20.165.94.63
- 4.150.223.108
- 20.236.44.162
- 40.103.64.242
- 52.123.128.14
- 135.232.92.34
- 203.26.79.13
- 51.132.193.104
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report