MALICIOUS — 5cad867bdf39d48b405444b779fb2f932fe65814cc107eb38522b36abbf49706
MALICIOUS — 5cad867bdf39d48b405444b779fb2f932fe65814cc107eb38522b36abbf49706 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
5cad867bdf39d48b405444b779fb2f932fe65814cc107eb38522b36abbf49706 - SHA-1:
a79dd5cf7199c2f854599941c9229831f724e89d - MD5:
906daa5d74652986e0e349c1bb5649a9 - ssdeep:
1536:8Moij6SFs34iQTWlWbrFw+MlHWpaM4Jq1fPjWcpOmudR5c/E3wD:Ls34LrwDGFfPCm4R5cc3I - TLSH:
T11738CFF32197CD5C739A9B47BAEA1258614ED38895B2EBE040C8766CC47C6BC3E10E11 - Submitted as: 5cad867bdf39d48b405444b779fb2f932fe65814cc107eb38522b36abbf49706
- File type: pdf · Size: 81612 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://reutlinger.pl/userfiles/file/wesazupunejitoxi.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 17 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://cycling-software.com/files/file/pavexigeg.pdf, http://decamiones.com/userfiles/file/54646967630.pdf, https://www.phoenixdentalacademy.co.uk/wp-content/plugins/super-forms/uploads/php/files/000278a64d1a8b567ebefe3088fc7ce7/kovixipuwo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9634 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787802381&P2=404&P3=2&P4=I2NXpfFnVRoLoe%2foNFsA6THjXX%2fnOZiy5S30WaE%2bVMTw1gIEiiljg6iQMhLvcDHlK2JU6O7PUOgM8A%2fyLg9WVQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787802392&P2=404&P3=2&P4=OBexzMGCBCXWovPfbGj8%2bOtFrvXWhuXFONiIorSMgtdT1wV6KwvjckSVP0%2fYVZxLU7nIoY9D3dIUHi2KXD90gQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787199114&P2=404&P3=2&P4=G2frZ8T83xWHnMFhQ%2bLrX8fwHHKYiJzZOeoJt0rBJo09v%2b28LSL7Crhzb3xhyOdzCqiZENDUhg26i%2bDeyR375Q%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
8368b6c3a289d6fcd99264066f9b0d99a79b7b01a9a578b88ed2d79af4eda479 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\4836268b2931fbd114589d8ba182da1d.png -
195e0f8ca76639fd9a3f505e2b76533509c267bd299c60bbb0948a6611fb5881 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/FevRqgeaUVY/uplcv?utm_term=linden+lea+sheet+music+pdf
- http://cycling-software.com/files/file/pavexigeg.pdf
- http://decamiones.com/userfiles/file/54646967630.pdf
- https://www.phoenixdentalacademy.co.uk/wp-content/plugins/super-forms/uploads/php/files/000278a64d1a8b567ebefe3088fc7ce7/kovixipuwo.pdf
- http://iideree.org/wp-content/plugins/formcraft/file-upload/server/content/files/1607a1d45403f4---xowesojewerinatu.pdf
- https://www.booster-p.com/wp-content/plugins/formcraft/file-upload/server/content/files/16082d554e4dea---36394244967.pdf
- http://www.oschouston.com/osc/wp-content/plugins/formcraft/file-upload/server/content/files/16092798d88592---xakugevizatabawer.pdf
- http://reutlinger.pl/userfiles/file/wesazupunejitoxi.pdf
- https://www.litesourcenc.com/wp-content/plugins/super-forms/uploads/php/files/f1c153518778c27d60dd39256bc31fc8/4334398593.pdf
- https://angelsstaff.com/uploads/file/59255030184.pdf
- http://kuppersbusch.hu/userfiles/files/jepapegesesabe.pdf
- https://mosoptagro.ru/wp-content/plugins/super-forms/uploads/php/files/5710110e136140515666de0211737196/61294537478.pdf
- https://simovi.mx/wp-content/plugins/formcraft/file-upload/server/content/files/1608e8c270cdc8---42098712475.pdf
- http://mtlebanon62.com/clients/5/5e/5ee551a8be14a26d7d76bc5e90dd1372/File/jeserukukonevazez.pdf
- https://dichvumayphoto.vn/webroot/img/files/pigipojetisavowur.pdf
- https://riverasphotovideo.com/wp-content/plugins/formcraft/file-upload/server/content/files/160860cfce2ab5---weloken.pdf
- https://ckmandarin.com/uploads/zetunivetifizokemop.pdf
- https://utilitydiscount.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bc57b049393---xanokajusonesuwaleka.pdf
- http://fittbike.hu/files/file/71873345893.pdf
- https://linhquan-group.com/upload/ck/files/rulimovalovewub.pdf
- http://allasclub.com/campannas/file/lelunufapego.pdf
- https://signika.pl/Upload/file/fatutabigogefopota.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- feedproxy.google.com
- cycling-software.com
- decamiones.com
- www.phoenixdentalacademy.co.uk
- iideree.org
- www.booster-p.com
- www.oschouston.com
- reutlinger.pl
- www.litesourcenc.com
- angelsstaff.com
- mosoptagro.ru
- simovi.mx
- mtlebanon62.com
- riverasphotovideo.com
- ckmandarin.com
- utilitydiscount.com
- linhquan-group.com
- allasclub.com
- signika.pl
- www.w3.org
- purl.org
- ns.adobe.com
- kuppersbusch.hu
- dichvumayphoto.vn
- fittbike.hu
Embedded IP addresses
- 57.155.104.224
- 4.247.188.224
- 52.230.60.54
- 40.84.85.40
- 4.230.171.124
- 13.89.179.12
- 135.232.92.137
- 135.233.95.144
- 52.123.129.14
- 40.103.64.226
- 40.99.133.242
- 74.178.76.44
- 203.26.79.13
- 52.123.252.248
- 20.42.65.90
- 40.79.163.155
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report