MALICIOUS — 50d374556783df7226af18d2f0bce31cba92aeff124fdd4d4a392c58f751e1c5
MALICIOUS — 50d374556783df7226af18d2f0bce31cba92aeff124fdd4d4a392c58f751e1c5 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
50d374556783df7226af18d2f0bce31cba92aeff124fdd4d4a392c58f751e1c5 - SHA-1:
490c6eaec0bdb8f8a740363a77a28434a0bb18bb - MD5:
39ee6f2ccc6b2b0b0dc692b69c6fe9dc - ssdeep:
1536:zpeADjlDYwdg+8r9wnarvpLgFgWF5mkqc1GFWOpOwrKWvP9Fn165U:lvtDXdgD9wnarvpLy/vDmCwrtFF1F - TLSH:
T15D39DFF37097EE8C368B9F832DBB519C9459D7886176D6904084B7ACC1B88FDAF10921 - Submitted as: 50d374556783df7226af18d2f0bce31cba92aeff124fdd4d4a392c58f751e1c5
- File type: pdf · Size: 86682 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 18 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: http://www.guaitoli.eng.br/wp-content/plugins/formcraft/file-upload/server/content/files/1613363dc53f50---10437568242.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://huntic.ru/uplcv?utm_term=clownfish+voice+changer+android, http://liluby.com/upload/file/gapekiles.pdf, https://tiemhoahaibara.com/data/dulieu/files/lulexoluwezobibolajexes.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9675 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787782568&P2=404&P3=2&P4=a%2byZRoV35SRr4oIsUZoJiIj53ufg2cltXH%2f%2bOSLoDFLat%2f3ypPesVtg8FCQL8Wlmmzk88nz5ZIIh7gAnJLY0Cg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\386f9032b09848b83800fa25d2027944.png -
04a0b4ca67f953afe0372609877f25766f30210656efb702848edc3c2f1f6462 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
835a3b41597f53e1cbea62dff28ab4df0e780f53284cf653b5719b83934d553d - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://huntic.ru/uplcv?utm_term=clownfish+voice+changer+android
- http://liluby.com/upload/file/gapekiles.pdf
- https://tiemhoahaibara.com/data/dulieu/files/lulexoluwezobibolajexes.pdf
- https://middletonchambers.com/ckfinder/userfiles/files/xaramiwepugokobagoso.pdf
- http://www.guaitoli.eng.br/wp-content/plugins/formcraft/file-upload/server/content/files/1613363dc53f50---10437568242.pdf
- https://ip-kamera-rendszer.nuttydog.hu/ckfinder/userfiles/files/wabegam.pdf
- https://alpasol.e-giant.net/upload/files/56754637623.pdf
- https://storage-in-motion.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613590a8cf5cd---48324136295.pdf
- https://akdenizokullari.k12.tr/wp-content/plugins/super-forms/uploads/php/files/jcaj4pkmuqnspe9ifg0d32ujd5/keginiwiv.pdf
- https://isabellepieman.com/userfiles/file/59088498563.pdf
- http://victorylimo1.com/wp-content/plugins/formcraft/file-upload/server/content/files/16134a5d9e00e3---sokegesewufomisuvivu.pdf
- https://panegovernance.com/ourprojects/chowki/UserFiles/file/gininedaxikowabomi.pdf
- http://buydecor.ru/uploads/files/nelawilepexegu.pdf
- https://aakritidigitals.com/userfiles/files/wuwasuwoga.pdf
- http://coumert.com/images/file/97032605624.pdf
- https://organicearthfiji.com/documents/file/wewelufulibaxumovurokod.pdf
- http://panda-es.tokyo/yamituki-n/uploads/files/37734288819.pdf
- http://wxeina.com/userfiles/files/xixebafujo.pdf
- https://almuhja.net/ckfinder/userfiles/files/bavomotixirasodusagaju.pdf
- https://nexapos.com/upload/files/48320724022.pdf
- http://www.aunay-sous-auneau.fr/ckfinder/userfiles/files/78629340642.pdf
- http://www.recetasyconsejos.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613c5bbe38f82---gojurukofitilof.pdf
- https://reazfarah.com/ckfinder/userfiles/files/78508622564.pdf
- https://sofupingame.com/calisma2/files/uploads/negobomewuxudilafesawo.pdf
- http://kuhomania.ru/ckfinder/userfiles/files/fedisatel.pdf
Embedded domains
- huntic.ru
- liluby.com
- tiemhoahaibara.com
- middletonchambers.com
- www.guaitoli.eng.br
- alpasol.e-giant.net
- storage-in-motion.com
- isabellepieman.com
- victorylimo1.com
- panegovernance.com
- buydecor.ru
- aakritidigitals.com
- coumert.com
- organicearthfiji.com
- wxeina.com
- almuhja.net
- nexapos.com
- www.aunay-sous-auneau.fr
- www.recetasyconsejos.com
- reazfarah.com
- sofupingame.com
- kuhomania.ru
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 57.154.63.210
- 20.42.65.93
- 162.159.142.9
- 52.110.12.10
- 4.144.132.114
- 52.110.12.42
- 4.230.171.124
- 4.150.223.107
- 74.178.240.61
- 52.123.128.14
- 40.99.133.226
- 135.233.45.223
- 74.179.71.159
- 203.26.79.13
- 51.105.71.137
- 48.199.12.1
- 52.168.117.171
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report