MALICIOUS — a55ed3a388f4a59f8ccf5a847fdd93c3207c64fbb9431a308d0b8821bead9a7d
MALICIOUS — a55ed3a388f4a59f8ccf5a847fdd93c3207c64fbb9431a308d0b8821bead9a7d is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a55ed3a388f4a59f8ccf5a847fdd93c3207c64fbb9431a308d0b8821bead9a7d - SHA-1:
8adb26c66463dfd33224bcb2669cc64b12c6018e - MD5:
1dfa633c3f2d0ae335757544de6d2ac5 - ssdeep:
3072:lLu10UOKP0UdT8gX59SpGJIJ023Fg4LOHFsjjHosDVu+5VLQvC9:010UgUZX59LJIJ91g4ylsjT3j7 - TLSH:
T1923BE0E330D7FD4CB34EAB4364EA1168A68DD7882062965046CCB59C84BCEFD7E95620 - Submitted as: a55ed3a388f4a59f8ccf5a847fdd93c3207c64fbb9431a308d0b8821bead9a7d
- File type: pdf · Size: 108302 bytes
- Verdict: malicious (98/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://motacademy.it/file/sixaroxanuleselivifudojip.pdf, https://stpetejazz.com/wp-content/plugins/super-forms/uploads/php/files/o5o2artijmsfu6odknda3jmj6k/jiwobuduv.pdf, https://40parables.com/wp-content/plugins/super-forms/uploads/php/files/fd7f2ba706c3d2d38cc70366170b4e33/83122360982.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 10 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1031 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.85
- 23.11.37.157
- 20.190.167.18
- 52.123.252.243 AU · Sydney · AS8075 Microsoft Corporation
- 52.110.12.48 AU · Sydney · AS8075 Microsoft Corporation
- 23.198.40.44
- 57.154.63.210 US · Phoenix · AS8075 Microsoft Limited UK
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.171
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/1xuhb7AK25c/uplcv?utm_term=how+to+heal+a+bee+sting+on+foot
- https://motacademy.it/file/sixaroxanuleselivifudojip.pdf
- https://stpetejazz.com/wp-content/plugins/super-forms/uploads/php/files/o5o2artijmsfu6odknda3jmj6k/jiwobuduv.pdf
- https://40parables.com/wp-content/plugins/super-forms/uploads/php/files/fd7f2ba706c3d2d38cc70366170b4e33/83122360982.pdf
- http://3dprofi.net/images/uploads/file/45741921365.pdf
- http://www.zopfitravel.com/wp-content/plugins/formcraft/file-upload/server/content/files/16079ad891206b---jizomezubazatadorej.pdf
- https://seerupit.dk/assens/file/genixasitadosigewizili.pdf
- http://www.iycadana.org/wp-content/plugins/super-forms/uploads/php/files/v3qajvp5du8957hbitaj4kba61/782305817.pdf
- https://earthideasawnings.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c8ee004d22b---28067833816.pdf
- http://dolphinegypt.net/userfiles/file/33889046843.pdf
- http://vincentpopetutoring.com/clients/d/dd/dd6b7bcf94cac99d3bed97cf8166637b/File/laviwox.pdf
- https://kaptenhoki.info/contents//files/vafometusemuvusufigeru.pdf
- https://www.jahnigterbraak.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160c85a181642f---balorelejoxerorunan.pdf
- http://ldbell1965.net/clients/85689/File/29218934340.pdf
- http://superfishinglewood.com/uploads/files/denebekemosatenezil.pdf
- https://kede.org/userfiles/file/rosuki.pdf
- http://royalwedding.jp/images/blog//file/29186162655.pdf
- http://www.luminicaambiental.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d1b1425a334---lixonon.pdf
- https://dacoma.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1609450cae0f29---semidotogiji.pdf
- http://robalton.es/Albums/images/file///77718263492.pdf
- https://presstone.hu/userfiles/file/7926269477.pdf
- https://promise-land.com/upload/file/53633293060.pdf
- https://cupanghitam.com/contents//files/8998342766.pdf
- https://mediabandit.com/wp-content/plugins/formcraft/file-upload/server/content/files/160cb3dc90b998---63987451862.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- motacademy.it
- stpetejazz.com
- 40parables.com
- 3dprofi.net
- www.zopfitravel.com
- www.iycadana.org
- earthideasawnings.com
- dolphinegypt.net
- vincentpopetutoring.com
- kaptenhoki.info
- www.jahnigterbraak.nl
- ldbell1965.net
- superfishinglewood.com
- kede.org
- royalwedding.jp
- www.luminicaambiental.com
- robalton.es
- promise-land.com
- cupanghitam.com
- mediabandit.com
- j.se
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.148.114.188
- 52.123.252.243
- 52.110.12.48
- 57.154.63.210
- 4.230.171.124
- 52.230.60.54
- 74.178.240.51
- 74.179.77.204
- 51.11.192.50
- 20.184.175.18
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report