MALICIOUS — ee316e1e95cf9747adb659918623d5beeb1f804eead0b07c2c711467c2438650
MALICIOUS — ee316e1e95cf9747adb659918623d5beeb1f804eead0b07c2c711467c2438650 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
ee316e1e95cf9747adb659918623d5beeb1f804eead0b07c2c711467c2438650 - SHA-1:
a12621c26406270e04a2386fbec6ea572f8b8b6a - MD5:
e449afc082dbd91b87ba44072d2ad4db - ssdeep:
1536:eWhee7YL7A719A+fnIuKNmYom1hHwYo2JMoiMdT1Q5jD7Gvu0Wp7NewtbWapOnzk:MyCAquSmtswYBJBiMdmPiudAwtEno - TLSH:
T19839D0F310A7DD6C72DACB0339EA229CE487DB9860629D4054C8763C95BC5BDBF10A61 - Submitted as: ee316e1e95cf9747adb659918623d5beeb1f804eead0b07c2c711467c2438650
- File type: pdf · Size: 86056 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://vnationwide.com/userfiles/files/5093885385.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 20 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://garglob.ru/uplcv?utm_term=side+by+side+book+2+pdf+free+download, http://yds-wcv.jp/free_images/files/23059835300.pdf, http://sithome.com/upfiles/file/20210917104821.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9658 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
970e61cd41ff58f48de59bae9c2f29831abd190f374d3ff68b20ae96af66bdc9 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\5d54eb382ea3cd7b988d0dd5ed9a607a.png -
ad7a7363f5ddf35bdbe63f0ecc6a24e5d432a0e287de0b5369e3ccf9c2697085 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://garglob.ru/uplcv?utm_term=side+by+side+book+2+pdf+free+download
- http://yds-wcv.jp/free_images/files/23059835300.pdf
- http://sithome.com/upfiles/file/20210917104821.pdf
- https://benqmusicworkshop.com/fupload/file/rafab.pdf
- http://vnationwide.com/userfiles/files/5093885385.pdf
- https://www.mercato.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/1613a75da06ea4---xadebefalaz.pdf
- https://registracijakoncar.com/webroot/js/ckfinder/userfiles/files/41003585226.pdf
- https://daaeportrett.no/upload/file/71150712881.pdf
- https://castilloexterior.es/ckfinder/userfiles/files/74757867500.pdf
- http://avision-italia.com/userfiles/files/davarujigutosefopososo.pdf
- http://kargo-box.com/uploads/files/22483196190.pdf
- https://equimat-cheval.fr/file/vidofawaneburasoguvolorun.pdf
- http://spzpoz-zdunskawola.pl/upload/file/46537149697.pdf
- http://weingut-suppan.at/files/71863973520.pdf
- http://bukharageorgia.com/sites/default/files/file/rezujawabasizepovevi.pdf
- http://andrenickels.de/ckfinder/userfiles/files/36818910457.pdf
- http://baohanhranghm.com/upload/img/files/4078285671.pdf
- http://coeb.eu/userfiles/files/xovaninekugefo.pdf
- http://musiclivemarsala.com/userfiles/files/walojodadebewibabexi.pdf
- http://fisioterapiasuzzara.it/userfiles/files/59384718936.pdf
- https://otdelkamos.ru/wp-content/plugins/super-forms/uploads/php/files/1556101b377efb573dd9c942bb8a28a4/44292885552.pdf
- http://cantinachitarra.it/userfiles/file/72187990863.pdf
- https://www.kiteschule-kiel.de/wp-content/plugins/formcraft/file-upload/server/content/files/16146883b6403b---20581104220.pdf
- http://mcutech.net/files/liretuxig.pdf
- https://my-natural-style.net/upload/files/63204965558.pdf
Embedded domains
- garglob.ru
- yds-wcv.jp
- sithome.com
- benqmusicworkshop.com
- vnationwide.com
- www.mercato.co.za
- registracijakoncar.com
- daaeportrett.no
- castilloexterior.es
- avision-italia.com
- kargo-box.com
- equimat-cheval.fr
- spzpoz-zdunskawola.pl
- bukharageorgia.com
- andrenickels.de
- baohanhranghm.com
- coeb.eu
- musiclivemarsala.com
- fisioterapiasuzzara.it
- otdelkamos.ru
- cantinachitarra.it
- www.kiteschule-kiel.de
- mcutech.net
- my-natural-style.net
- www.canadiantreasurer.com
Embedded IP addresses
- 20.184.175.1
- 4.150.223.100
- 172.172.255.216
- 52.123.252.233
- 40.84.97.4
- 4.230.171.124
- 172.215.188.225
- 20.247.184.142
- 20.165.94.63
- 135.232.92.97
- 20.231.239.246
- 52.123.129.14
- 135.234.160.244
- 52.123.252.202
- 72.145.35.97
- 203.26.79.13
- 52.123.252.245
- 48.200.63.27
- 52.168.112.67
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report