MALICIOUS — 94949975838.pdf
MALICIOUS — 94949975838.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e38bf393d0a49757513194aa97f4ad686430472983704403674f6c84d3daae21 - SHA-1:
24ce1b88438fba5be1c5a8ae6c6d24b66f3a5ee4 - MD5:
0db626aa23d1c615bdec0e008a75d499 - ssdeep:
1536:zgxok5LuPLmizM2McDkde7cy0rc1tJ/WkNpOPUUhgiiWMv9zM+7TwQjn:8xruPLfycGe7cynOPUhi0zHwC - TLSH:
T1F638D0F310EFDF4C678B9F836AEB055CA886D284256293904484B65CC5BC8BDBF50A61 - Submitted as: 94949975838.pdf
- File type: pdf · Size: 82737 bytes
- Verdict: malicious (95/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 17 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://infrive.ru/uplcv?utm_term=lecture+notes+in+networks+and+systems, http://evabody.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1609820e4dc635---33183527757.pdf, http://uro-medical.pl/zdjecia/fotki/file/10954815757.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9660 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
378be71b9ef9d7f9580d8e524374764bbdd670f5c779b5cd29eac899e8430dd2 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\41ee6ce0274604643561e6e490e62593.png -
94c23a6f771c7912aa4a5906c1d6454777d544efd8548cc75cd5de6ce029bda9 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://infrive.ru/uplcv?utm_term=lecture+notes+in+networks+and+systems
- http://evabody.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1609820e4dc635---33183527757.pdf
- http://uro-medical.pl/zdjecia/fotki/file/10954815757.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/16080655a83727---sirozibidejaw.pdf
- https://vizzzio.ru/wp-content/plugins/super-forms/uploads/php/files/1ff61abee99119b42083afe6b0d194c3/91553479445.pdf
- http://skup-laptopow.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ad3a1e11d82---nepubajulibixedaz.pdf
- http://3gr-group.com/ci/userfiles/files/67997095799.pdf
- https://saunadlaciebie.pl/userfiles/file/2199282549.pdf
- https://autosofortkauf.ch/wp-content/plugins/super-forms/uploads/php/files/3lpk92s00cdr7mklakiums6k5t/pusexesisufuw.pdf
- https://bienenaktuell.com/sites/bienenaktuell.com/files/file/45739310978.pdf
- http://gdaniec.com/upload/files/xanewujelutikajotis.pdf
- http://www.tif.cn/wp-content/plugins/super-forms/uploads/php/files/nb4djk0fek3g77bqshqcqm8nvo/55489076080.pdf
- http://www.carolglassman.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c358730fc8c---rolopuv.pdf
- https://sellerflows.com/wp-content/plugins/super-forms/uploads/php/files/d6d98fa145dfb978e74ce337ecb5227d/19858640090.pdf
- https://www.electriclighting.com/wp-content/plugins/super-forms/uploads/php/files/f3c543d53a9fc0c46e9b27c83cde249c/jonititesafatixuja.pdf
- https://moto-trend.cz/public/files/fck/file/maviviwopugosanob.pdf
- http://www.alex-vasilkov.ru/images/wisdom/file/75292774283.pdf
- https://www.karavanlakesfet.com/wp-content/plugins/super-forms/uploads/php/files/824c9d40d911bd73e296fbe3cd772951/xupafafijewufubidad.pdf
- https://www.penyembuhanholistikreiki.com/wp-content/plugins/formcraft/file-upload/server/content/files/160983d9b9aace---3626987891.pdf
- https://a5productions.com/home/a5pro/public_html/ckfinder/userfiles/files/115718240.pdf
- http://getawaynewzealand.co.nz/wp-content/plugins/formcraft/file-upload/server/content/files/160b3df719e199---boluresakubadafeginef.pdf
- http://logiccpacma.com/ckfinder/userfiles/files/91117514740.pdf
- http://bucketdiaries.com/uploads/files/fagufo.pdf
- http://noithattamphuong.com/upload/files/bonudizekogomisujopul.pdf
- https://marljivo.hr/userfiles/file/ditipu.pdf
Embedded domains
- infrive.ru
- uro-medical.pl
- www.1000ena.com
- vizzzio.ru
- skup-laptopow.com
- 3gr-group.com
- saunadlaciebie.pl
- autosofortkauf.ch
- bienenaktuell.com
- gdaniec.com
- www.tif.cn
- www.carolglassman.com
- sellerflows.com
- www.electriclighting.com
- www.alex-vasilkov.ru
- www.karavanlakesfet.com
- www.penyembuhanholistikreiki.com
- a5productions.com
- logiccpacma.com
- bucketdiaries.com
- noithattamphuong.com
- www.w3.org
- purl.org
- ns.adobe.com
- evabody.ro
Embedded IP addresses
- 4.150.223.96
- 40.84.85.40
- 57.155.101.212
- 4.230.171.124
- 4.150.223.108
- 74.178.232.29
- 72.145.35.107
- 52.123.128.14
- 203.26.79.13
- 74.179.77.204
- 40.103.64.242
- 20.89.1.9
- 4.209.250.170
- 4.247.188.224
- 52.123.252.215
- 52.123.129.14
- 20.184.175.9
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report