MALICIOUS — facf2b6dfbe1202280cd9467299541f0f33cfd0a3fc58b2b490b4e769735d2c3
MALICIOUS — facf2b6dfbe1202280cd9467299541f0f33cfd0a3fc58b2b490b4e769735d2c3 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
facf2b6dfbe1202280cd9467299541f0f33cfd0a3fc58b2b490b4e769735d2c3 - SHA-1:
0f1d556d46c73a1686db377012026d846d51c46c - MD5:
62059fc14edc55da1f8d62c6dd984585 - ssdeep:
1536:iu2djKrcmY9vP81P2c3RGjQmuiMj4ybsEaAmQHm/QyfyEasE7r:L2NKYz9XaR598lE9mQHmzyhjr - TLSH:
T10A38DFF32197DC5DA89BDB4399A2002D704BE3446033DAC458D8F62CD1BC6EEBE54422 - Submitted as: facf2b6dfbe1202280cd9467299541f0f33cfd0a3fc58b2b490b4e769735d2c3
- File type: pdf · Size: 78696 bytes
- Verdict: malicious (95/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!62059FC14EDC
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 23 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://inwebjor.ru/uplcv?utm_term=rufus+for+windows+7+32+bit+free+download, https://sgdivorcelawyers.com/wp-content/plugins/super-forms/uploads/php/files/ab2e4bbdd41d520f6a954b6c99a16fb8/8098540483.pdf, https://fellowpeo.com/wp-content/plugins/super-forms/uploads/php/files/a56e33ca9eda5b90d7561dd8bcad0f3c/25622340358.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (15 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9812 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787847049&P2=404&P3=2&P4=E3b9f9hX5mPpVz%2fHmx2423Lq9c9AopcVnXgAqCLJ2dV8O7%2fQdpdVULVvveu20FZT1oLjC2%2b2lVRDnAc1U%2b1trw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787847114&P2=404&P3=2&P4=cTO4Vgv5N5H7zYpLw6uEV1N868w5WWXDYtxzax6On2loJLxZO3HPZvzV7Ay9S94NIX0%2fI7bg8lBVUB3n2%2bDNVg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\397726b65ed2da87467d04bb78d805cf.png -
3fa510b58c15b51022d4b0fa4bece97e5847f592aebb956489c46962790f2a96 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
4a2948e9ca1f78896709f3d6decf05063d9bae43daaafbda92a04ebc04c2af50 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://inwebjor.ru/uplcv?utm_term=rufus+for+windows+7+32+bit+free+download
- https://sgdivorcelawyers.com/wp-content/plugins/super-forms/uploads/php/files/ab2e4bbdd41d520f6a954b6c99a16fb8/8098540483.pdf
- https://fellowpeo.com/wp-content/plugins/super-forms/uploads/php/files/a56e33ca9eda5b90d7561dd8bcad0f3c/25622340358.pdf
- https://smoothnomad.com/wp-content/plugins/super-forms/uploads/php/files/jmg67g5p60pb0q0fr8q47isi06/tazolibasidumefedasizapob.pdf
- http://musorcentrum.hu/files/article/file/93293488238.pdf
- http://www.lavalledesign.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608aeac167366---potuzumezekifavabelogi.pdf
- https://www.lightingsolutionsinc.net/wp-content/plugins/super-forms/uploads/php/files/0d0a970b1e715fb79609d26addcc592e/87904062884.pdf
- https://leicht-spb.ru/wp-content/plugins/super-forms/uploads/php/files/1f9bf9948d6aebb85b2c418535b04df5/76433423619.pdf
- https://www.lightingdynamics.com/wp-content/plugins/super-forms/uploads/php/files/908c76ba172d9dfef6cb51c5478c4cf2/86142412905.pdf
- https://revapackers.com/wp-content/plugins/super-forms/uploads/php/files/6mh8kea4nco5aqbpftsdietcno/xoxavuzifosaxivuwo.pdf
- https://fitnessrev.net/wp-content/plugins/super-forms/uploads/php/files/ali4t38c89i27p9oto888ldnkh/58134913763.pdf
- https://arizonapoolcontractor.com/wp-content/plugins/formcraft/file-upload/server/content/files/16085e53dda5af---lekezanamaxuvuzexowunonab.pdf
- http://www.marsagri.com/wp-content/plugins/formcraft/file-upload/server/content/files/160883710dee77---58113741777.pdf
- http://israel-aliya.com/wp-content/plugins/super-forms/uploads/php/files/cc0080766b1f12cefe97be83dc5a409b/52755684523.pdf
- http://musorcentrum.hu/files/article/file/wepixutoketoze.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Embedded domains
- inwebjor.ru
- sgdivorcelawyers.com
- fellowpeo.com
- smoothnomad.com
- www.lavalledesign.com
- www.lightingsolutionsinc.net
- leicht-spb.ru
- www.lightingdynamics.com
- revapackers.com
- fitnessrev.net
- arizonapoolcontractor.com
- www.marsagri.com
- israel-aliya.com
- www.w3.org
- purl.org
- ns.adobe.com
- musorcentrum.hu
Embedded IP addresses
- 74.178.240.61
- 20.42.65.93
- 52.123.252.215
- 52.110.12.26
- 52.110.12.5
- 52.230.60.54
- 4.230.171.124
- 52.123.252.219
- 135.233.95.80
- 72.145.35.98
- 203.26.79.13
- 135.232.92.137
- 74.179.77.204
- 52.123.129.14
- 40.99.133.210
- 135.233.45.222
- 104.208.16.94
- 4.150.223.105
- 52.123.252.226
- 92.223.78.30
- 135.232.92.34
- 48.192.143.121
- 51.104.15.253
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report