MALICIOUS — 1608b861539b44---wodenikotebiga.pdf
MALICIOUS — 1608b861539b44---wodenikotebiga.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e94ecc78cd9f06eda5c269b5081ac1c84fff653d9d7feb4510612600552feaa1 - SHA-1:
6482bfd57a9c5b9abb460252110d9ff60c0ed49c - MD5:
6bda8554255442f6d9ef2c7f5c6ff8d4 - ssdeep:
1536:V7O2x7mGyGDGno8s7h1XDoIUjOkC3Zuh3uoP16Bq9mNUuxYQ:9O2xbyqGnOFpUTS8h3uivgNUux - TLSH:
T15337C0F75197DD5CAF86EF0399E6102C240AE7881133E7A54188BAACE9BC77D5D04CA0 - Submitted as: 1608b861539b44---wodenikotebiga.pdf
- File type: pdf · Size: 74603 bytes
- Verdict: malicious (95/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!6BDA85542554
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 15 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://visualpaint.com/wp-content/plugins/formcraft/file-upload/server/content/files/160820fc047314---53659890666.pdf, http://totalfinance.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1607abdaf6dc7c---93007983805.pdf, http://www.photobreak.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16077b7e636001---tozesuwokujado.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (17 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9755 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
8342c160f50555bfc171861e5214dec444a67385d5b68c3d4249f1029da67630 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\909b637759ccb18a7aeef8d6bf8db560.png -
527ea8a62f764774dea7b091401e4bccd4e58bb7a367dd5676f952618170683f - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/FevRqgeaUVY/uplcv?utm_term=vande+mataram+song+in+tamil+free
- http://visualpaint.com/wp-content/plugins/formcraft/file-upload/server/content/files/160820fc047314---53659890666.pdf
- http://totalfinance.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1607abdaf6dc7c---93007983805.pdf
- http://www.photobreak.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16077b7e636001---tozesuwokujado.pdf
- https://medicinasolidale.org/wp-content/plugins/super-forms/uploads/php/files/0f07f973c7f8bcbcd388c33b33df0f28/sufedamakuzukakagafu.pdf
- https://afd.me.uk/wp-content/plugins/super-forms/uploads/php/files/i507enqt8tee7tp30nmcb0k116/71463782275.pdf
- http://bjoybrands.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606d8fe1b9290---femibalasilagowemuxugew.pdf
- http://asalsold.com/wp-content/plugins/formcraft/file-upload/server/content/files/16075b48daf776---javerawuwafigabegog.pdf
- https://skazkavdom.com/wp-content/plugins/super-forms/uploads/php/files/a3a757fc280e5bb24e226ebad60e857f/35262495592.pdf
- https://chicagoportablexray.com/wp-content/plugins/formcraft/file-upload/server/content/files/160706218cc5bf---7489222304.pdf
- http://www.chinahkcarplate.com/wp-content/plugins/formcraft/file-upload/server/content/files/16087bb2c87839---80911859112.pdf
- https://www.sehersirin.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607cffe788ad5---vumafisenobujiro.pdf
- https://unosms.us/userfiles/file/53410846315.pdf
- https://www.myjamaicais.com/wp-content/plugins/super-forms/uploads/php/files/dcadd4d2838477b96f0de195a88d8c35/90860689166.pdf
- http://mijneigenlift.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16081e4e1bd1c1---jedezesizega.pdf
- http://audiomaster.se/wp-content/plugins/formcraft/file-upload/server/content/files/160804f00957b4---bapolisobizugepumusupef.pdf
- https://lsp.od.ua/wp-content/plugins/super-forms/uploads/php/files/leldfqndel14fdm02ugsj0sh33/63822120595.pdf
- https://avenirpourtous.fr/wp-content/plugins/formcraft/file-upload/server/content/files/1606f840c4a32a---nixadotimila.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- feedproxy.google.com
- visualpaint.com
- totalfinance.ca
- www.photobreak.com.br
- medicinasolidale.org
- afd.me.uk
- bjoybrands.com
- asalsold.com
- skazkavdom.com
- chicagoportablexray.com
- www.chinahkcarplate.com
- www.sehersirin.com
- unosms.us
- www.myjamaicais.com
- mijneigenlift.nl
- audiomaster.se
- lsp.od.ua
- avenirpourtous.fr
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 172.172.255.216
- 20.184.175.18
- 52.110.12.5
- 52.230.60.54
- 4.230.171.124
- 172.215.188.232
- 4.150.223.100
- 135.232.92.137
- 20.112.250.133
- 52.123.128.14
- 40.99.134.2
- 135.233.45.223
- 20.165.94.46
- 203.26.79.13
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report