MALICIOUS — 92552c55a7075c14e0af3645ccbdc508fce3c44d0f3affcf36c086d9d5f3ee7f
MALICIOUS — 92552c55a7075c14e0af3645ccbdc508fce3c44d0f3affcf36c086d9d5f3ee7f is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
92552c55a7075c14e0af3645ccbdc508fce3c44d0f3affcf36c086d9d5f3ee7f - SHA-1:
119c511e53aade4210318db635da6872c1a3eee7 - MD5:
77bd1dc0665d6573bca14fa73b604bf7 - ssdeep:
1536:pmmBgY1jZtOsbPLhN4EgFCT/oWx3W6flWd7/mkVZ:MqpOWEEmCT/h3xfIKi - TLSH:
T15A37BFF3229FED4C79878F43B8DA50B42489D7885132EAA040C8BB7C98BC5BC7911B51 - Submitted as: 92552c55a7075c14e0af3645ccbdc508fce3c44d0f3affcf36c086d9d5f3ee7f
- File type: pdf · Size: 74782 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 22 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://alpasol.e-giant.net/upload/files/bekijoxowoweliso.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://iphysiology.ru/upload/fejopafesalaramev.pdf, http://nceed.kr/pds/userfiles/files/79877229638.pdf, https://www.puskinas.lt/ckfinder/userfiles/files/44630391896.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9652 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\d798788aa2528a1b19c60ebe9c8af86c.png -
7af853d142310f66342fdb550e34b5d3d0173dbf31c3919e233a069c13b40409 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
b8d00cb89129f2bb30417088c1c26698f5d8c138fe248863d86cbbe3afa6b70e - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- http://feedproxy.google.com/~r/Xvkpad/~3/vItLtdF7Pec/uplcv?utm_term=how+to+edit+pdf+documents+in+windows+10
- http://iphysiology.ru/upload/fejopafesalaramev.pdf
- http://nceed.kr/pds/userfiles/files/79877229638.pdf
- https://www.puskinas.lt/ckfinder/userfiles/files/44630391896.pdf
- http://forumcutuca.com/ckfinder/userfiles/files/xirasejufavonufixibavudid.pdf
- http://cocoal.com/uploads/file/62001850024.pdf
- https://genesisbehaviorcenter.com/wp-content/plugins/super-forms/uploads/php/files/bc1bb53ebc6da4c997df4dd89f53d2f8/bemolagumakodabuserotutu.pdf
- http://szybkieprawko.pl/szybkieprawko.pl/user/admin/fck/file/dilupuwirupa.pdf
- http://elistaprezentow.pl/userfiles/file/duvujamemevaxapat.pdf
- https://grahampropertytax.com/wp-content/plugins/super-forms/uploads/php/files/c04c5341e737736c09ac33828f9977e2/229889262.pdf
- https://alpasol.e-giant.net/upload/files/bekijoxowoweliso.pdf
- http://zgic.ru/!upload/files/kinuwiliratugevi.pdf
- http://oprandi.it/userfiles/files/silaworagezofebukugujet.pdf
- https://praktijkbinnenstad.nl/file/jakidinarerivizu.pdf
- http://decorstore.eu/upload/file/wuvinizow.pdf
- http://bvphcn.bdata.vn/upload/files/23835755999.pdf
- http://1472bond.com/upload/Fckeditor/file/vasulewiromimagijefufu.pdf
- https://balajihighfields.in/userfiles/file/jadikonazejizibe.pdf
- http://www.korayozelguvenlik.com/wp-content/plugins/formcraft/file-upload/server/content/files/16158629d37ba5---85079885855.pdf
- http://chip-chup.hu/upload/file/88565273070.pdf
- http://kartinatv.org/uploads/files/vamesasefajesixago.pdf
- http://dostrojar.sk/UserFiles/file/suzelo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- feedproxy.google.com
- iphysiology.ru
- nceed.kr
- forumcutuca.com
- cocoal.com
- genesisbehaviorcenter.com
- szybkieprawko.pl
- elistaprezentow.pl
- grahampropertytax.com
- alpasol.e-giant.net
- zgic.ru
- oprandi.it
- praktijkbinnenstad.nl
- decorstore.eu
- 1472bond.com
- balajihighfields.in
- www.korayozelguvenlik.com
- kartinatv.org
- www.w3.org
- purl.org
- ns.adobe.com
- www.puskinas.lt
- bvphcn.bdata.vn
- chip-chup.hu
- dostrojar.sk
Embedded IP addresses
- 4.150.223.101
- 20.184.175.10
- 52.123.252.247
- 52.110.12.31
- 52.110.12.21
- 85.210.196.11
- 4.230.171.124
- 203.26.79.13
- 4.144.132.114
- 135.232.92.137
- 20.165.94.54
- 74.178.76.128
- 52.123.252.231
- 20.76.201.171
- 52.123.129.14
- 52.123.128.14
- 135.233.45.223
- 20.165.94.46
- 20.184.175.23
- 172.170.180.133
- 52.168.112.66
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report