MALICIOUS — c05a716c3cd87489f706ed9ec18be2f74d7fc57c87f019f05183a8ad31a58956
MALICIOUS — c05a716c3cd87489f706ed9ec18be2f74d7fc57c87f019f05183a8ad31a58956 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
c05a716c3cd87489f706ed9ec18be2f74d7fc57c87f019f05183a8ad31a58956 - SHA-1:
fdc3f90923b3662f751bb963e7c9f71d0e11e233 - MD5:
676bc83b8713cf576717c2c278c3e1c9 - ssdeep:
768:oVb9FBOFBmAuEkQB3TuuXsYggTmXn+blIq2JL2bfLUF9uxbaHatTRnarO6/lcW2E:ohyBPkZuXOEnbl5/bIkbJtt2R6WRr - TLSH:
T14E33AFE350B39D0CB74F4E42B9D71BAF598EE74890A7E0A4814C5729C1ECA7F6E09901 - Submitted as: c05a716c3cd87489f706ed9ec18be2f74d7fc57c87f019f05183a8ad31a58956
- File type: pdf · Size: 48368 bytes
- Verdict: malicious (98/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://scuolascifondocortinadolomiti.it/userfiles/files/22230232719.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 20 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://archism.ru/uplcv?utm_term=xposed+parallel+space, https://cedd.saglik-network.org/uploads/file/59992749262.pdf, https://seo-methodes.com/userfiles/file/zojefasadavejipuke.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
5622 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- c.pki.goog
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
9cb52477319b08a37676e9ec3402a99f5a5efeb80598d1bf5d022ce691518e95 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://archism.ru/uplcv?utm_term=xposed+parallel+space
- https://cedd.saglik-network.org/uploads/file/59992749262.pdf
- https://seo-methodes.com/userfiles/file/zojefasadavejipuke.pdf
- http://www.chiringuitomediterraneo.com/ckfinder/userfiles/files/96692218771.pdf
- http://fairfresh.net/assets/admin/ckeditorimage/files/34677334891.pdf
- http://scuolascifondocortinadolomiti.it/userfiles/files/22230232719.pdf
- https://tavcam.com/upload/ckfinder/files/26655091985.pdf
- http://oilmachineydy.com/d/files/gewedobut.pdf
- http://www.studiolegalefusimorelli.com/wp-content/plugins/formcraft/file-upload/server/content/files/161480bcca1dda---8120404104.pdf
- http://goodfortune.hk/UpLoadFile/file///jawubulasizajowopovam.pdf
- http://inlikeflintlogistics.com/wp-content/plugins/formcraft/file-upload/server/content/files/161421bc513867---jikaxuzenabagukenoj.pdf
- http://xn--80aa5alfu.kz/file/29738031637.pdf
- http://kamienneogrody.com/userfiles/file/87636606007.pdf
- https://hardlineconstruct.ro/app/webroot/files/userfiles/files/pigusulekoturudagagurelab.pdf
- https://revive.fashion/upload/files/99568871675.pdf
- http://motolargo.pl/userfiles/file/12006398491.pdf
- http://rajskiewakacje.pl/userfiles/file/wexawunaxujod.pdf
- http://qdxqw.com/uploadfile/file/kipiguwebedogevinorefu.pdf
- http://classiccar-jp.com/js/upload/files/75534106283.pdf
- http://titibbs.xyz/js/ckfinder/userfiles/files/varofulebadarero.pdf
- http://www.megasaludips.com/wp-content/plugins/formcraft/file-upload/server/content/files/16152e4f7b2823---37795360435.pdf
- https://dla-pracownika.pl/pliki_user/File/dukekudasituguvitazoje.pdf
- http://lucidareemantenerepavimentifaidate.it/userfiles/files/85582446041.pdf
- https://rhdplumbing.com/wp-content/plugins/super-forms/uploads/php/files/7692a97c7a806a5e6728f27817fb7e77/modewarifomi.pdf
- http://wjcopy.com/upload/files/zazumu.pdf
Embedded domains
- archism.ru
- cedd.saglik-network.org
- seo-methodes.com
- www.chiringuitomediterraneo.com
- fairfresh.net
- scuolascifondocortinadolomiti.it
- tavcam.com
- oilmachineydy.com
- www.studiolegalefusimorelli.com
- goodfortune.hk
- inlikeflintlogistics.com
- kamienneogrody.com
- motolargo.pl
- rajskiewakacje.pl
- qdxqw.com
- classiccar-jp.com
- titibbs.xyz
- www.megasaludips.com
- dla-pracownika.pl
- lucidareemantenerepavimentifaidate.it
- rhdplumbing.com
- wjcopy.com
- demowz.reikor.com
- xn--80aa5alfu.kz
- hardlineconstruct.ro
Embedded IP addresses
- 74.178.76.128
- 72.154.7.110
- 4.150.223.97
- 104.208.16.94
- 20.184.175.12
- 52.123.252.212
- 52.123.252.234
- 74.178.76.44
- 85.210.193.152
- 4.230.171.124
- 52.253.84.76
- 72.154.7.96
- 203.26.79.13
- 135.233.95.144
- 52.168.117.174
- 52.123.252.233
- 40.99.133.226
- 52.123.128.14
- 52.123.252.235
- 48.200.63.27
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report