MALICIOUS — ef1d7c8548fa03cac10676fade6ffee29cb5da45c97b8674a60c2cb8355ac218
MALICIOUS — ef1d7c8548fa03cac10676fade6ffee29cb5da45c97b8674a60c2cb8355ac218 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
ef1d7c8548fa03cac10676fade6ffee29cb5da45c97b8674a60c2cb8355ac218 - SHA-1:
ce640d530a855063d529c9ce5416acbcc044ffa7 - MD5:
4f7e01787a491af57a045ba1d3a2870d - ssdeep:
1536:6V7onzi7llgq5SYBy9mECblZ+VRXqDZmgdp5B0cpxhuDA0VAiVkqM:O0n0lKqk3mEClZ6F8jde+huDN/V6 - TLSH:
T17538D0F32187EE4CBACF9B4369AA753D244DD3547137A6A0448C762DC4BC36DAE20A50 - Submitted as: ef1d7c8548fa03cac10676fade6ffee29cb5da45c97b8674a60c2cb8355ac218
- File type: pdf · Size: 80063 bytes
- Verdict: malicious (98/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!4F7E01787A49
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/2fe0136c-dc11-4ad9-bb1e-d9c5e5422d62/what_could_cause_battery_light_to_come_on.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 17 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://krisoc.ru/pbw?utm_term=shooting+bench+ideas, https://uploads.strikinglycdn.com/files/2fe0136c-dc11-4ad9-bb1e-d9c5e5422d62/what_could_cause_battery_light_to_come_on.pdf, https://nagofojog.weebly.com/uploads/1/3/4/5/134586362/4234688.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (12 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9720 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787917846&P2=404&P3=2&P4=WvhkSs72eEJSdObnrePxFma7zaSN%2bjuTcFSh3otbkYIb7YOTyOrtfMwNyz4ztdYi997NFqwfKdbvaUAhbskQuw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787917890&P2=404&P3=2&P4=SEqe%2b6KvbPI5cisRGaXOI7s5FFl1X8StyaAib0cMALiYL%2bnovltL4dAOQ6tPMvGkfUQMVArvkcUoW6k3pmfREw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\2821f449161e29a5b531dd7763ea3939.png -
a4e2415828d82a088bbbe5d21c1af9a2c60d3f2a9ceaba3d8205905f14d6b7ba - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
0be5cebb41641042212c1f22d9852e52d7ecee991461e24ffa1facff60da971a - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://krisoc.ru/pbw?utm_term=shooting+bench+ideas
- https://uploads.strikinglycdn.com/files/2fe0136c-dc11-4ad9-bb1e-d9c5e5422d62/what_could_cause_battery_light_to_come_on.pdf
- https://nagofojog.weebly.com/uploads/1/3/4/5/134586362/4234688.pdf
- https://uploads.strikinglycdn.com/files/3fb46e6c-329b-4661-bb9f-b64bff9611d7/how_to_access_my_cloud_from_pc.pdf
- http://dazokarodu.pbworks.com/f/39987261131.pdf
- http://nuxawakaxaz.pbworks.com/w/file/fetch/144527208/evaluation_sur_la_revolution_francaise_et_lempire_4eme.pdf
- https://jojimixumomural.weebly.com/uploads/1/3/4/4/134438106/b8043d7dd52.pdf
- https://lofuniwap.weebly.com/uploads/1/3/0/8/130874201/fomunebitogu.pdf
- https://uploads.strikinglycdn.com/files/f3d92f58-ef2e-46d1-9c52-84d5ee638918/burr_v._2003_social_constructionism.pdf
- https://uploads.strikinglycdn.com/files/eae4a516-5427-4be0-9bb2-e3a2a4048088/best_acoustic_guitar_songs_chords_lyrics.pdf
- https://vamabeloketofip.weebly.com/uploads/1/3/4/3/134344852/xedirelugatovukakaj.pdf
- https://mirebaxowani.weebly.com/uploads/1/3/4/0/134017623/6ddfacc3b.pdf
- https://uploads.strikinglycdn.com/files/67bcbad6-4740-408d-b5d4-b17c4d21362b/what_are_the_5_types_of_infectious_agents.pdf
- https://desivisigoxup.weebly.com/uploads/1/3/4/6/134681557/9995524.pdf
- https://xokojitijuxup.weebly.com/uploads/1/3/4/3/134362284/sofifa-ledugutugam.pdf
- http://gamaxidad.pbworks.com/f/92554242300.pdf
- https://uploads.strikinglycdn.com/files/ed08b566-afb0-4e03-996c-cb48eabc1178/sony_mdr_rf985rk_price_in_india.pdf
- https://sejirefado.weebly.com/uploads/1/3/4/6/134682993/5843511.pdf
- https://uploads.strikinglycdn.com/files/80626ae6-abf7-4690-852e-f64ef64bbd37/fight_club_chuck_palahniuk_book_review.pdf
- http://gabumur.pbworks.com/w/file/fetch/144932817/jafare.pdf
- https://uploads.strikinglycdn.com/files/c3691105-af16-41b2-8c27-a4271e3baa07/electrolux_refrigerator_owners_manual.pdf
- https://maverutorolo.weebly.com/uploads/1/3/5/3/135393183/dabugexuk.pdf
- https://bixevojug.weebly.com/uploads/1/3/0/7/130739122/rofevorunekuw.pdf
- https://uploads.strikinglycdn.com/files/1f1d948f-4a37-4a6d-9f5b-f60826bc6c65/power_of_information_quotes.pdf
- https://uploads.strikinglycdn.com/files/33be76be-3518-4448-82e6-b7e651e430d1/medical_imaging_physics_book.pdf
Embedded domains
- krisoc.ru
- uploads.strikinglycdn.com
- nagofojog.weebly.com
- dazokarodu.pbworks.com
- nuxawakaxaz.pbworks.com
- jojimixumomural.weebly.com
- lofuniwap.weebly.com
- vamabeloketofip.weebly.com
- mirebaxowani.weebly.com
- desivisigoxup.weebly.com
- xokojitijuxup.weebly.com
- gamaxidad.pbworks.com
- sejirefado.weebly.com
- gabumur.pbworks.com
- maverutorolo.weebly.com
- bixevojug.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 172.178.240.162
- 172.237.146.49
- 20.165.94.46
- 20.247.184.197
- 4.230.171.124
- 72.153.5.97
- 203.26.79.13
- 135.232.92.137
- 40.79.141.155
- 52.123.252.219
- 20.231.239.246
- 52.123.128.14
- 20.42.65.89
- 48.192.143.121
- 20.42.73.28
- 4.150.223.113
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report