MALICIOUS — 5fa17f4c466f0e769ea8e844f9ca4cc2becacc865d2e137b24842710cffe7fe2
MALICIOUS — 5fa17f4c466f0e769ea8e844f9ca4cc2becacc865d2e137b24842710cffe7fe2 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
5fa17f4c466f0e769ea8e844f9ca4cc2becacc865d2e137b24842710cffe7fe2 - SHA-1:
1e8672e8492d366f940da9131433e6a0fc5e81e3 - MD5:
10465107167760e53c440bb55d37856c - ssdeep:
3072:IryBaP6VQ1DjkSFhdZIDBfVCwBlIlEiimL1e:IryPOnNZs97r - TLSH:
T1B03CE1F300DBED1C778AEB43A5E6109D654EEB484232FAD00148EB6C94BC67E7E14A51 - Submitted as: 5fa17f4c466f0e769ea8e844f9ca4cc2becacc865d2e137b24842710cffe7fe2
- File type: pdf · Size: 117444 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 20 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: http://asbu.net/uploads/FCK_files/file/23225130677.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://bmat.mn/uploads/ckfinder/files/vofagusadunegawa.pdf, https://powermailer.in/userfiles/file/tadoxeruzif.pdf, https://nada70.org/userfiles/file/xazudetotosubudi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9733 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787800544&P2=404&P3=2&P4=Ya9Xw%2beuncHDd%2b4svrhTLtsrbEKOIKZXsWGXjyqhX%2fGK9PnkM5PRDcSsOxvnFWq5JtFx45vT6kY59rQDm6D8sA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
2416095f4f7a97ca03b5818e3b342b217916b239b392492d01382e1660fe1192 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\d195331f3f524cf67a183934543c8ca2.png -
ea30a22f664e949d62483ad69946298efe0e62b096cbadd82c419f2346a6bc1a - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/YTWXjIUwRh0/uplcv?utm_term=fnaf+world+update+2+download+unblocked
- https://bmat.mn/uploads/ckfinder/files/vofagusadunegawa.pdf
- https://powermailer.in/userfiles/file/tadoxeruzif.pdf
- https://nada70.org/userfiles/file/xazudetotosubudi.pdf
- http://www.trimbleexpress.sk/wp-content/plugins/formcraft/file-upload/server/content/files/1608c1dd611cc5---80689722922.pdf
- https://propbrains.com/wp-content/plugins/super-forms/uploads/php/files/rj80ukvfgv8ruh7pgjtuhlfof4/bipokedakirivofinu.pdf
- https://actioncoach.com.my/wp-content/plugins/formcraft/file-upload/server/content/files/160ed2b6237174---jawiketedeleretukufetado.pdf
- http://asbu.net/uploads/FCK_files/file/23225130677.pdf
- http://feynburg-uhren.de/uploads/14225439217.pdf
- https://mygenius.ru/admin/ckfinder/userfiles/files/ripoge.pdf
- https://southtours.com/wp-content/plugins/super-forms/uploads/php/files/50cpc9q0okkpm914suie0l7tnc/29238526749.pdf
- http://elm3rad.com/file/kidep.pdf
- http://glenbrooksouth1970.com/clients/1/17/17fc1bd13d5538a69f39d58c869d2fc5/File/lezarekoruwopig.pdf
- https://www.sacda.org/wp-content/plugins/super-forms/uploads/php/files/n51ae0h0mbiae5dubqv8264n13/daxarugowibijelozelug.pdf
- https://www.capitalroofingct.com/wp-content/plugins/formcraft/file-upload/server/content/files/16089e05d9129f---notiz.pdf
- http://koreaseowon.com/ckupload/files/32303868817.pdf
- https://artofsurfing.com/preview/ckfinder/userfiles/files/88632437251.pdf
- https://www.osteopathe-montpellier-sud.fr/ckfinder/userfiles/files/22420074624.pdf
- https://pluckywize.com/wp-content/plugins/formcraft/file-upload/server/content/files/160f355af16afd---90482883141.pdf
- https://www.mclarenpress.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607b32bf2edec---jidomuxijozaxetu.pdf
- http://akinmedical.com/uploads/file/rofuf.pdf
- http://kusadasidentalclinic.com/img/userfiles/files/895636365.pdf
- https://ercrs.org/wp-content/plugins/super-forms/uploads/php/files/vohbv30irbnrbj5o3gg5q0nv2j/xuxinemorixegaseva.pdf
- https://europartner2.pl/uploads/81339120176.pdf
- https://janeunchained.com/wp-content/plugins/super-forms/uploads/php/files/9mk7cvgu43chcvc57i8k9dcers/zizotiz.pdf
Embedded domains
- feedproxy.google.com
- powermailer.in
- nada70.org
- propbrains.com
- asbu.net
- feynburg-uhren.de
- mygenius.ru
- southtours.com
- elm3rad.com
- glenbrooksouth1970.com
- www.sacda.org
- www.capitalroofingct.com
- koreaseowon.com
- artofsurfing.com
- www.osteopathe-montpellier-sud.fr
- pluckywize.com
- www.mclarenpress.com
- akinmedical.com
- kusadasidentalclinic.com
- ercrs.org
- europartner2.pl
- janeunchained.com
- timebank.ru
- www.w3.org
- purl.org
Embedded IP addresses
- 4.150.223.99
- 20.42.73.27
- 172.66.2.5
- 4.150.223.103
- 52.110.12.15
- 52.110.12.46
- 4.230.171.124
- 135.233.95.80
- 52.253.84.76
- 203.26.79.13
- 20.165.94.54
- 20.231.239.246
- 74.178.240.61
- 52.123.128.14
- 40.99.134.18
- 135.233.45.223
- 172.175.111.170
- 52.182.141.63
- 20.42.65.93
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report