MALICIOUS — nidab.pdf
MALICIOUS — nidab.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100). 4 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
c0d89c42155bed014615e5332d50844cd9c5e17fb3f16b0c86e56fdb25e977fa - SHA-1:
1ae2c94db3ca3d3711a183cf319c87004080447e - MD5:
8333a5a048f5d3c31a002defcaee53a0 - File type: pdf · Size: 86098 bytes
- Verdict: malicious (100/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Dynamic analysis (windows)
9740 behavior events · 1 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786553843&P2=404&P3=2&P4=i8WxZH4hMuKiO%2f4Iqre0gXtF5Ao6beukxovKy%2f6gKGBtQ46Bbg5yT7WEkQ3l7tMUiZJF%2bWlyLSYkR6CAln05ew%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786553888&P2=404&P3=2&P4=F0uIs2nwculxoUgsh61TGoJFb3omG9AELcLOfRfeNNwEcRqgY%2bXgGr5MzuUnSNNj89Dc%2bp0GFhFevMaqOZ4vNA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- 192.168.122.116
- 23.40.52.85
- 23.11.37.157
- 20.190.142.163
- 150.171.22.17
- 23.33.238.135
Dropped files
- /opt/CAPEv2/storage/analyses/13666/files/2fa1ddeb3a43162d76a29d3da02b0b0b0684e290d3730545ef26a5ace700c3da —
2fa1ddeb3a43162d76a29d3da02b0b0b0684e290d3730545ef26a5ace700c3da - /opt/CAPEv2/storage/analyses/13666/files/319d6b5cc475a03bf88166f01c23100933f90360b86ddfbd79e48f95c6245f1f —
319d6b5cc475a03bf88166f01c23100933f90360b86ddfbd79e48f95c6245f1f - root_.cache_dconf_user —
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.wFXlkl4zBs —
ed9a9f6b4796b674ccdc58a4524cf326759864993cfdb65539de40667384932c
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/3vuEKuznOb8/uplcv?utm_term=chemical+composition+of+materials+pdf
- http://nuyewrecruitment.com/wp-content/plugins/super-forms/uploads/php/files/4af293741c213bab0bf5d815caa48182/xebazetisoli.pdf
- http://fratellilongoni.com/userfiles/files/giwelubifalufe.pdf
- http://mclarenquartz.in/ci/userfiles/files/84044069200.pdf
- http://canhtoanland.com/upload/files/fesemubujutogevepijoju.pdf
- http://christembassydocklands.org/wp-content/plugins/super-forms/uploads/php/files/2281710edb7253fbab7db95200c3926d/44093652671.pdf
- https://www.andrecampbell.ca/wp-content/plugins/super-forms/uploads/php/files/e191fbb0d27da2bdbd8ecaaf843fcc8c/zinezite.pdf
- http://edgecs.net/documents/toxutovebokadomejumoxukor.pdf
- http://milcontabil.com.br/wp-content/plugins/super-forms/uploads/php/files/830b1viu6cdd2pkcahk6jifm62/12299240078.pdf
- https://qualitylightsolutions.com/wp-content/plugins/super-forms/uploads/php/files/ecf7d9f8e8f490c64875fc91f452dde7/fofadigugagizutiwef.pdf
- http://bassbasement.org/userfiles/file/bujuwawinukomodi.pdf
- http://marthomaiticherukole.com/userfiles/file/mugimigofaxulimom.pdf
- https://www.adelaarenergy.com/wp-content/plugins/super-forms/uploads/php/files/fm4atuba6qr9grsumbtuot4150/2691982757.pdf
- https://pacpartner.net/images_client//imagesfile/tadapasovimamibinexus.pdf
- https://mercedesmazo.es/wp-content/plugins/formcraft/file-upload/server/content/files/1607caf9d57a56---wofifukuvebekoped.pdf
- https://lawpropertyconsultants.co.uk/wp-content/plugins/super-forms/uploads/php/files/del57adacrpcd2llfnfmdf63cv/zabefajuvudaki.pdf
- http://samuiluxurytravel.com/Uploads/file/pudikimejubuwemarak.pdf
- http://lbs.ac.at/wp-content/plugins/super-forms/uploads/php/files/ptiatib5fv150bj079nc0uki44/puzepozewubiwusuxuvonivu.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/1611734425cb53---lokazipowixofotepeze.pdf
- http://zjhywt.com/images/upload/File/61829053370.pdf
- http://stylist.in.ua/wp-content/plugins/formcraft/file-upload/server/content/files/1608bf18d5a7a5---badatukojopidakidosula.pdf
- https://machnhaduong.com/images/uploads/files/88958593341.pdf
- http://solyaris.pro/admin/ckfinder/userfiles/files/dosifuxebiliv.pdf
- https://chokysitohang.com/Uploads/userfiles/files/sajanizubujitikenutawufen.pdf
- http://carlaschroyen.com/content_docs/7665394850.pdf
Embedded domains
- feedproxy.google.com
- nuyewrecruitment.com
- fratellilongoni.com
- mclarenquartz.in
- canhtoanland.com
- christembassydocklands.org
- www.andrecampbell.ca
- edgecs.net
- milcontabil.com.br
- qualitylightsolutions.com
- bassbasement.org
- marthomaiticherukole.com
- www.adelaarenergy.com
- pacpartner.net
- mercedesmazo.es
- lawpropertyconsultants.co.uk
- samuiluxurytravel.com
- www.1000ena.com
- zjhywt.com
- stylist.in.ua
- machnhaduong.com
- solyaris.pro
- chokysitohang.com
- carlaschroyen.com
- retentionstudentexperience.com
Embedded IP addresses
- 74.178.240.61
- 52.123.252.247
- 20.42.179.192
- 52.110.12.10
- 4.230.171.124
- 52.253.84.76
- 48.211.4.16
- 74.178.76.128
- 13.69.116.104
- 172.178.240.163
- 74.178.76.44
- 203.26.79.13
- 92.223.78.30
- 149.154.167.99
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report