MALICIOUS — 5d6fd4955a52a0e5b16304bb7e4a0098087bc24aec3107fce09382e45ecde8c5
MALICIOUS — 5d6fd4955a52a0e5b16304bb7e4a0098087bc24aec3107fce09382e45ecde8c5 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100). 3 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5d6fd4955a52a0e5b16304bb7e4a0098087bc24aec3107fce09382e45ecde8c5 - SHA-1:
cc813c58f6917e51d989863371dc8ba751ab2820 - MD5:
83d17556bdd03d094ae4a45f69a0eec4 - ssdeep:
3072:fhX6RZxO4OtNGGY+aU4fhoFWSObmnMHCOUCk:fhK/xs5Y+aUMW7Omx - TLSH:
T18F3BD1F31097DE5C764B8B1368E6019C6486D7C81133AEB060C9B69CC9AC9FD7E44A21 - Submitted as: 5d6fd4955a52a0e5b16304bb7e4a0098087bc24aec3107fce09382e45ecde8c5
- File type: pdf · Size: 107991 bytes
- Verdict: malicious (89/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 89/100 is the fusion of 8 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.icodar.com/wp-content/plugins/formcraft/file-upload/server/content/files/160f0290682fbb---12842968035.pdf, http://grupposcorcia.it/userfiles/files/dinolaseberebe.pdf, http://praguetransfer.com/files/file/nilazigig.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 11 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1016 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- _dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
- 20.190.167.149
- 192.168.122.112
- 52.123.252.212 AU · Sydney · AS8075 Microsoft Corporation
- 23.33.238.178
- 23.198.40.44
- 4.144.132.114 SG · Singapore · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.171
- 23.33.238.100
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/BvfzZFkJO3s/uplcv?utm_term=coc+loot+time
- http://www.icodar.com/wp-content/plugins/formcraft/file-upload/server/content/files/160f0290682fbb---12842968035.pdf
- http://grupposcorcia.it/userfiles/files/dinolaseberebe.pdf
- http://praguetransfer.com/files/file/nilazigig.pdf
- http://omonetach.pl/foto/ilustracje/file/bomuzivoregarukufi.pdf
- https://transcendenceit.com/wp-content/plugins/super-forms/uploads/php/files/b741e76ea076737e8caef2b938498cdd/19829155273.pdf
- https://realestateconnect.us/wp-content/plugins/super-forms/uploads/php/files/akgi3gvvmmk79d80sdfedkrog5/jesowezutavijuru.pdf
- http://partnercable.hu/files/86456808392.pdf
- http://cameranichietsu.com/luutru/files/34799631141.pdf
- https://teenvolunteerdallas.org/wp-content/plugins/super-forms/uploads/php/files/f194fb172d020a41c8b463a51f053e6d/xularabujerofaxarudewa.pdf
- https://hasekei.jp/userfiles/file/sivubidomoxijoda.pdf
- http://gapoom.com/upload/fckeditor/file/wekutoji.pdf
- https://balticstroy.com/uploads/files/pujeveburaraw.pdf
- https://niboparis.com/upload/fckeditor/files/69171987034.pdf
- https://conexus-study-abroad-travel.com/ckfinder/userfiles/file/dowufozaxoligijoxukegib.pdf
- http://svs-pm.com/wp-content/plugins/formcraft/file-upload/server/content/files/160768a211a6da---46020601333.pdf
- https://hafa-verein.de/wp-content/plugins/super-forms/uploads/php/files/43212e3237ac9396377e9887a7b0a1b3/1159660868.pdf
- http://elisa5888.com/shopadmin/upload/files/puzodevewukubotovuw.pdf
- https://hitpoint.tw/userfiles/file/12934849135.pdf
- http://perfect-gallery.com/userfiles/file/foneroferilasivobivuwita.pdf
- https://hoffmanowska.pl/wp-content/plugins/formcraft/file-upload/server/content/files/160aeb0f14c81c---46171975908.pdf
- http://astro2sphere.com/admin/images/file/bugatukoti.pdf
- http://uat.ideadunes.com/projects/ideadunes-portfolio-site/wp-content/plugins/formcraft/file-upload/server/content/files/160b457c569b35---21966069146.pdf
- https://www.carlosfunes.es/wp-content/plugins/formcraft/file-upload/server/content/files/1609eaaf4a55b2---51881840667.pdf
- http://ancheng-medical.com//uploadfile/files/xoxamofesawigojuw.pdf
Embedded domains
- feedproxy.google.com
- www.icodar.com
- grupposcorcia.it
- praguetransfer.com
- omonetach.pl
- transcendenceit.com
- realestateconnect.us
- cameranichietsu.com
- teenvolunteerdallas.org
- hasekei.jp
- gapoom.com
- balticstroy.com
- niboparis.com
- conexus-study-abroad-travel.com
- svs-pm.com
- hafa-verein.de
- elisa5888.com
- hitpoint.tw
- perfect-gallery.com
- hoffmanowska.pl
- astro2sphere.com
- uat.ideadunes.com
- www.carlosfunes.es
- ancheng-medical.com
- www.w3.org
Embedded IP addresses
- 203.26.79.13
- 4.247.188.224
- 4.150.223.114
- 20.42.179.204
- 52.123.252.212
- 4.144.132.114
- 4.230.171.124
- 40.79.163.155
- 20.184.175.7
- 20.50.201.195
- 20.42.179.192
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report