MALICIOUS — 56770560c63de9be9a2710d855e5d6fd49842b7e2bf0a2e545c298921c78bf9e
MALICIOUS — 56770560c63de9be9a2710d855e5d6fd49842b7e2bf0a2e545c298921c78bf9e is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
56770560c63de9be9a2710d855e5d6fd49842b7e2bf0a2e545c298921c78bf9e - SHA-1:
23ec095c2028f8e6b09416a5f10935e0f4fc4b6c - MD5:
6c811ba5218f05d77ed5443baeb2c8a5 - ssdeep:
1536:VtZt8GbXskX3SiXgCkttjR81skz8/mQ/Gfxsyh/0kgjczuVC:Nt8GDR3S8gCkttexhmGZsyhcktN - TLSH:
T17B38D0F35297CE4C7ADA8F4775EB255C588AD3492427EB90208C7A6C84EC7AD3D20D12 - Submitted as: 56770560c63de9be9a2710d855e5d6fd49842b7e2bf0a2e545c298921c78bf9e
- File type: pdf · Size: 81437 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!6C811BA5218F
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 17 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://1682489e-d94b-4f22-b6a6-c8ecb623ca2e.filesusr.com/ugd/5f226e_b95f163082fa4d9aafa297d7cc34c44b.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://golowaki.ru/strik?utm_term=how+to+factory+reset+iomega+storcenter+ix2, https://cdn.sqhk.co/pepupiribojo/cqyLOhc/gifonijamoruwum.pdf, http://nizavevorupuj.mywebcommunity.org/chinese_picture_dictionary.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9686 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
6a96b7da69c7abfca8010dc50f079a70a26ebacff686baf7da1df0268952a2c3 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\eba5198a97a285bd58c93028c5bdb94b.png -
33bbe2d241abf01e27cd89f8acec7a49cace5f98aa84ee5dbdab8bcd2daba20e - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://golowaki.ru/strik?utm_term=how+to+factory+reset+iomega+storcenter+ix2
- https://cdn.sqhk.co/pepupiribojo/cqyLOhc/gifonijamoruwum.pdf
- http://nizavevorupuj.mywebcommunity.org/chinese_picture_dictionary.pdf
- http://xevijojikutep.onlinewebshop.net/43101437298.pdf
- http://fobexugelego.getenjoyment.net/is_dunkin_donuts_always_hiring.pdf
- https://1682489e-d94b-4f22-b6a6-c8ecb623ca2e.filesusr.com/ugd/5f226e_b95f163082fa4d9aafa297d7cc34c44b.pdf?index=true
- https://cdn.sqhk.co/pozigafo/ciav8jc/ludetiju.pdf
- http://natbeach.space/pimorerewiwolaxabubezuduw4szd.pdf
- http://dithetsen.xyz/50864282290qtyr2.pdf
- http://barbanapoli.moscow/wixulinijusqaqlg.pdf
- http://nakozek.mypressonline.com/autodesk_inventor_animation_tutorial.pdf
- https://cdn.sqhk.co/depifozopupe/Ijciige/black_diamond_london_ontario.pdf
- http://takovevagagiv.scienceontheweb.net/tratamiento_cancer_de_tiroides.pdf
- https://cdn.sqhk.co/kusasuzona/heSehht/49835336089.pdf
- https://234a0c07-d908-4261-bb83-16b3c96a9b04.filesusr.com/ugd/73e0e6_c6c739703987481b8a3aa1cb1fbddfbd.pdf?index=true
- https://f37c3615-20b0-4e70-b1e7-2acf34113780.filesusr.com/ugd/1e533a_c6f080df221e4466b0e0e1b5ec756fd9.pdf?index=true
- http://relivoziz.atwebpages.com/edit_files_free_software.pdf
- https://16564176-4c62-44d7-82e3-1dea6b832d73.filesusr.com/ugd/5e57cf_206924ebc5214c27823240d9337fab75.pdf?index=true
- http://trynutra.shop/how_to_reset_consumer_cellular_phonehwvdz.pdf
- http://ottics.ru/802956866960903s.pdf
- http://zedebegeku.myartsonline.com/zibuduladubed.pdf
- https://cdn.sqhk.co/wefonasifaza/Lzijijx/32743938549.pdf
- http://pifadopagel.scienceontheweb.net/atcc_animal_cell_culture_guide.pdf
- https://cdn.sqhk.co/mowamukar/kp22bie/75739599529.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- golowaki.ru
- cdn.sqhk.co
- nizavevorupuj.mywebcommunity.org
- xevijojikutep.onlinewebshop.net
- fobexugelego.getenjoyment.net
- 1682489e-d94b-4f22-b6a6-c8ecb623ca2e.filesusr.com
- natbeach.space
- dithetsen.xyz
- nakozek.mypressonline.com
- takovevagagiv.scienceontheweb.net
- 234a0c07-d908-4261-bb83-16b3c96a9b04.filesusr.com
- f37c3615-20b0-4e70-b1e7-2acf34113780.filesusr.com
- relivoziz.atwebpages.com
- 16564176-4c62-44d7-82e3-1dea6b832d73.filesusr.com
- trynutra.shop
- ottics.ru
- zedebegeku.myartsonline.com
- pifadopagel.scienceontheweb.net
- www.w3.org
- purl.org
- ns.adobe.com
- barbanapoli.moscow
Embedded IP addresses
- 51.132.193.105
- 172.172.255.218
- 20.42.65.88
- 52.123.252.213
- 52.110.12.19
- 20.247.185.124
- 4.230.171.124
- 72.153.5.61
- 203.26.79.13
- 74.178.240.51
- 74.178.240.61
- 52.123.128.14
- 74.178.232.29
- 92.223.78.30
- 57.154.63.210
- 172.170.180.133
- 51.116.253.170
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report