MALICIOUS — 5a10e374f489fb69198ba8b54e25cc3bc1eb0ccd61ff8d09e4ab6ab0e2be1495
MALICIOUS — 5a10e374f489fb69198ba8b54e25cc3bc1eb0ccd61ff8d09e4ab6ab0e2be1495 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5a10e374f489fb69198ba8b54e25cc3bc1eb0ccd61ff8d09e4ab6ab0e2be1495 - SHA-1:
dd3dd6876ffc63176a80b6ebe2b8f8bc57fec8e5 - MD5:
ebfafcb92eb56c0032ab5178c4955306 - ssdeep:
1536:JtiUSGe8nrHV/MlME5Y0YPv9lJlXWGPu9F3W+uT/WOpOwrbz9DS0vO:Wgr1/2fYZPl/NMk+q8wrZA - TLSH:
T1AB37CFF76097EF5C734B8B4799DF21AD704AD7886672EA8001C8676C88BC4BDBB14640 - Submitted as: 5a10e374f489fb69198ba8b54e25cc3bc1eb0ccd61ff8d09e4ab6ab0e2be1495
- File type: pdf · Size: 72652 bytes
- Verdict: malicious (98/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://betenagro.com/sites/default/files/file/kipujazupovaloliju.pdf, http://kartinatv.org/uploads/files/zuxaputasegexuxoxivebolew.pdf, http://patanjali.zohukum.com/ckfinder/userfiles/files/pasasuxijasekilotomewok.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 10 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1301 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.85
- 23.11.37.157
- 20.190.167.19
- 192.168.122.107
- 52.123.252.248 AU · Sydney · AS8075 Microsoft Corporation
- 52.110.12.42 AU · Sydney · AS8075 Microsoft Corporation
- 23.33.238.178
- 23.198.40.44
- 172.215.188.225 US · San Antonio · AS8075 Microsoft Limited
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/3CAf4wW3hvY/uplcv?utm_term=super+sound+app
- https://betenagro.com/sites/default/files/file/kipujazupovaloliju.pdf
- http://kartinatv.org/uploads/files/zuxaputasegexuxoxivebolew.pdf
- http://patanjali.zohukum.com/ckfinder/userfiles/files/pasasuxijasekilotomewok.pdf
- http://resetimpianti.it/reset/public/file/zifulizol.pdf
- http://wakabaeducation.com/userfiles/file/mexumitakobonake.pdf
- http://botosani.ro/img/uploads/file/vifudap.pdf
- https://aquariumfargo.com/wp-content/plugins/super-forms/uploads/php/files/cb42a26c688cfa769098e8c38e3c971c/namilifogotimomimol.pdf
- http://assessmentinsight.com/ckfinder/userfiles/files/73779205550.pdf
- http://seasonmediagroup.com/pic/file/94779295596.pdf
- https://akemi.ro/hirek/file/88486310605.pdf
- http://bjyhyy.cn/filespath/files/20210925220226.pdf
- https://amezdigital.com/wp-content/plugins/super-forms/uploads/php/files/39ba3bf3a723b7498cd91c344d188843/pukulavajuzapopesepixad.pdf
- http://idealhca.com/admin/images/file/pekunote.pdf
- http://namjapizza.com/app/webroot/files/9979359618.pdf
- http://gccde.com/downloads/blog/geust/files/73331131523.pdf
- http://ratchadatitan.com/UserFiles/File/69268935260.pdf
- http://lynxauto.ru/userfiles/file/fekulemel.pdf
- https://hkbca.org/UploadFiles/file/20210910071531107.pdf
- http://robvancampen.nl/userfiles/file/subotawidadevesawid.pdf
- http://www.opencalgary.org/wp-content/plugins/formcraft/file-upload/server/content/files/1613f032fe3935---vitiroxuwatutimenozoni.pdf
- http://www.ks-klinika.ru/ckfinder/userfiles/files/suxutevamejexabolabo.pdf
- https://mebelpozakazu.ru/wp-content/plugins/super-forms/uploads/php/files/b3e27ddd1987c65bc2219c817006dd70/wamajejujibuzolexazul.pdf
- http://tksvolga.ru/userfiles/file/68935005810.pdf
- https://laps.pl/userfiles/file/vewipixufilepar.pdf
Embedded domains
- feedproxy.google.com
- betenagro.com
- kartinatv.org
- patanjali.zohukum.com
- resetimpianti.it
- wakabaeducation.com
- aquariumfargo.com
- assessmentinsight.com
- seasonmediagroup.com
- bjyhyy.cn
- amezdigital.com
- idealhca.com
- namjapizza.com
- gccde.com
- ratchadatitan.com
- lynxauto.ru
- hkbca.org
- robvancampen.nl
- www.opencalgary.org
- www.ks-klinika.ru
- mebelpozakazu.ru
- tksvolga.ru
- laps.pl
- www.w3.org
- purl.org
Embedded IP addresses
- 52.123.252.248
- 52.110.12.42
- 172.215.188.225
- 4.230.171.124
- 20.247.184.142
- 135.232.92.97
- 74.178.240.61
- 52.182.141.63
- 20.42.65.88
- 72.154.7.104
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report