MALICIOUS — 52080e2b56d84697e1643c91dd06f1286e25683e8e42c033f970813506f93947
MALICIOUS — 52080e2b56d84697e1643c91dd06f1286e25683e8e42c033f970813506f93947 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
52080e2b56d84697e1643c91dd06f1286e25683e8e42c033f970813506f93947 - SHA-1:
2175319250dc5c4499c63a110b42d43fe1c0c259 - MD5:
c836258498efa876a3af40c25f42385f - ssdeep:
1536:H9NUf/pJ2hij3jDlScATsgbcU7tMezOYo95fk2g9sWspORGW461xDoo7wqJ:43i4j3UdsgbT7tqkP9HRa2xx5 - TLSH:
T14037C0F3219BDD8C774B5F8369EA15B9608EE3889961EF100088B77C98BC8BD7E44550 - Submitted as: 52080e2b56d84697e1643c91dd06f1286e25683e8e42c033f970813506f93947
- File type: pdf · Size: 72955 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 19 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: http://velapower.com/glwh/UploadFile/file/2021090414163873499.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://allseasonsart.com/uploads/fck_uploads/file/biwagen.pdf, http://lilit-realty.com/wp-content/plugins/super-forms/uploads/php/files/sfl8l67buldtcradhqmi2gno00/32457521442.pdf, http://velapower.com/glwh/UploadFile/file/2021090414163873499.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9771 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787922372&P2=404&P3=2&P4=kRYiUm1B9xFoLn2yvUz8Xk%2bohlRpchEjKBCHRk8gUdQ%2b4yWLiZT7wziPynInCGyGLMi5InhYkTg6Z2paUEGzTg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787922420&P2=404&P3=2&P4=CeCIXioMidx9CIwIYHqgx6zFrW4pzrfcpJGbiTlnUY21mk2IbF8o6bfneHQhJnp%2bu%2bobNMV7JxBXRcsFtw9D6w%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
f6d8ff6c6d861b3fbf845ca85b8752ac71c80fcc0277d89cadefed00450d8b88 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\f82a6001cd6866fbd9539d3fa1a09f73.png -
cb8d9ed8edd9e1ef9a9597d7a63905ccdcebabe1e1ee566ecfe0b2436a716766 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/FevRqgeaUVY/uplcv?utm_term=economic+globalization+examples
- http://allseasonsart.com/uploads/fck_uploads/file/biwagen.pdf
- http://lilit-realty.com/wp-content/plugins/super-forms/uploads/php/files/sfl8l67buldtcradhqmi2gno00/32457521442.pdf
- http://velapower.com/glwh/UploadFile/file/2021090414163873499.pdf
- https://youxsoft.com/uploads/files/kuwelinawewukekoje.pdf
- http://aktifbant.com/resimler/files/9051177397.pdf
- https://patc.fr/imagesfile/sitikukexoz.pdf
- http://rebeccafantarchitetto.it/userfiles/files/suruverimejajal.pdf
- https://manorhair.com/uploads/files/202109151921489171.pdf
- https://eurouniversal.eu/ckfinder/userfiles/files/51536878674.pdf
- https://newegys.egyseg.eu/ckfinder/userfiles/files/xalegebimenenipurivadera.pdf
- http://www.rupankar.com/fckimages/file/37039513888.pdf
- https://stcc-sa.com/motakamel/Ups/files/27206988475.pdf
- http://imaginove.eu/data/Files/tijuxugoxojiseguk.pdf
- http://www.hkqi.com/wp-content/plugins/formcraft/file-upload/server/content/files/1615774fc9cd7e---79787723506.pdf
- http://bamboomfi.com/htdocs/cljr/data/files/pojesa.pdf
- https://nbtele.com/en/cache/fck_files/file/nolenenukimulixurasal.pdf
- http://babijie.com/upload_fck/file/2021-10-7/20211007050704788664.pdf
- https://giriconsultancy.com/content_files/files/tegitofexuliwaki.pdf
- http://rbc-bezorgdiensten.nl/upload/22985524154.pdf
- http://henzefashion.com/userfiles/file/55903142079.pdf
- http://opalbiosciences.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614e3c5252d4e---20191662317.pdf
- http://metzpaintings.com/wp-content/plugins/formcraft/file-upload/server/content/files/161303ab5791db---mokobutuxugozox.pdf
- http://steelfurniturecn.com/d/files/30418355236.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- allseasonsart.com
- lilit-realty.com
- velapower.com
- youxsoft.com
- aktifbant.com
- patc.fr
- rebeccafantarchitetto.it
- manorhair.com
- eurouniversal.eu
- newegys.egyseg.eu
- www.rupankar.com
- stcc-sa.com
- imaginove.eu
- www.hkqi.com
- bamboomfi.com
- nbtele.com
- babijie.com
- giriconsultancy.com
- rbc-bezorgdiensten.nl
- henzefashion.com
- opalbiosciences.com
- metzpaintings.com
- steelfurniturecn.com
- www.w3.org
Embedded IP addresses
- 52.168.117.169
- 52.123.252.220
- 172.66.2.5
- 20.42.179.192
- 4.144.132.223
- 4.230.171.124
- 74.179.77.204
- 74.179.77.164
- 74.178.240.61
- 52.123.128.14
- 40.99.133.242
- 40.104.4.2
- 172.178.240.163
- 72.153.5.140
- 203.26.79.13
- 4.150.223.111
- 20.42.65.91
- 20.42.73.26
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report