MALICIOUS — 525558ca48816e7e4bcd1928408c528df160bf4f7b582c5da036ab92f642200c
MALICIOUS — 525558ca48816e7e4bcd1928408c528df160bf4f7b582c5da036ab92f642200c is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
525558ca48816e7e4bcd1928408c528df160bf4f7b582c5da036ab92f642200c - SHA-1:
db665591b02b69c90e7523c5c3da5b33f669859d - MD5:
675b73f5e6fce4d6a39f926f223439d0 - ssdeep:
1536:V+cmBiO3qSNnjqWR3tklqEYobC7+M+fevFCeWapOtQHWb7i681ccLbAN:YcmHaS1hR3GliobC7+pfedCjtQ8vLcLW - TLSH:
T17C38D0E320D7DE1CB79FAF4365FA059DA54AE3886162EE604048B67CC07CA7D6E00951 - Submitted as: 525558ca48816e7e4bcd1928408c528df160bf4f7b582c5da036ab92f642200c
- File type: pdf · Size: 79024 bytes
- Verdict: malicious (98/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://catamma.ru/uplcv?utm_term=android+phones+spying+on+you, https://oancora.com/ckfinder/files/23387089829.pdf, http://massvt.sk/editor_uploads/system/files/keboridazileburorala.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 8 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
994 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- _dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
- 20.190.167.19
- 184.84.165.136 AU · Sydney · AS20940 Akamai Technologies, Inc.
- 52.110.12.46 AU · Sydney · AS8075 Microsoft Corporation
- 52.230.59.222 SG · Singapore · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.114
- 150.171.27.11
- 23.221.133.185
- 192.168.122.109
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://catamma.ru/uplcv?utm_term=android+phones+spying+on+you
- https://oancora.com/ckfinder/files/23387089829.pdf
- http://massvt.sk/editor_uploads/system/files/keboridazileburorala.pdf
- https://pypconsultores.mx/userfiles/file/29690031151.pdf
- http://snbedu.com/uploadfile/file///2021091514513012.pdf
- https://hurghadalife.net/userfiles/files/zidefebukopuluf.pdf
- https://catherinehourihan.art/wp-content/plugins/super-forms/uploads/php/files/e05ec321a15586d65df32b95461422e7/lijotejugemi.pdf
- http://ajej.pretty-match.com/upload/files/falifafosoberor.pdf
- http://spartaksedlec.cz/spartaksedlec/userfiles/file/xobixavi.pdf
- https://haps.company/wp-content/plugins/super-forms/uploads/php/files/f545ab9c7e89a65aae138e875b7bf67a/92375663842.pdf
- http://25630638.kad.tw/kads/ckfinder/userfiles/files/durefivesobamorur.pdf
- http://longarmquiltingacadamy.com/fckeditor/userfiles/file/saruderu.pdf
- http://arenabilardo.com/data/_files/saketufi.pdf
- https://www.prshots.com/ckfinder/userfiles/files/xafewurate.pdf
- https://noukos.gr/wp-content/plugins/formcraft/file-upload/server/content/files/1614274e0b7717---80607420842.pdf
- http://zhongjiukeji.com/upload_fck/file/2021-9-13/20210913143630367329.pdf
- https://nepalipublisher.com/ckfinder/userfiles/files/ruxaperosoxabaripopodu.pdf
- http://erisalaw-chicago.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/77152572984.pdf
- https://bosgo.mn/uploads/files/91483155386.pdf
- http://oticonshop.com/ckfinder/userfiles/files/zejesajugulugemepuxotawaz.pdf
- http://pieseclimaauto.com/files/file/37351718342.pdf
- http://khachsandomino.com/hinhanh_fckeditor/file/fewatasemuwana.pdf
- http://www.waetsukai.jp/system/ckfinder/userfiles/files/riletukenugumiz.pdf
- https://seroinstitute.com/wp-content/plugins/super-forms/uploads/php/files/ef1ce6f67dfc0d623bd33aa99dcf9775/84145508124.pdf
- http://anhuishangbiao.com/upload_fck/file/2021-9-10/20210910040422709853.pdf
Embedded domains
- catamma.ru
- oancora.com
- pypconsultores.mx
- snbedu.com
- hurghadalife.net
- ajej.pretty-match.com
- 25630638.kad.tw
- longarmquiltingacadamy.com
- arenabilardo.com
- www.prshots.com
- zhongjiukeji.com
- nepalipublisher.com
- erisalaw-chicago.com
- oticonshop.com
- pieseclimaauto.com
- khachsandomino.com
- www.waetsukai.jp
- seroinstitute.com
- anhuishangbiao.com
- igigeothermal.jp
- www.w3.org
- purl.org
- ns.adobe.com
- massvt.sk
- catherinehourihan.art
Embedded IP addresses
- 203.26.79.13
- 51.132.193.104
- 52.168.117.174
- 172.172.255.217
- 184.84.165.136
- 52.110.12.46
- 52.230.59.222
- 4.230.171.124
File paths
- b:\3n
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report