MALICIOUS — c4d2ccc4b547f2c14f6d581d9c4dd00090a5513bc64ae141198a6cdeb0279bdb
MALICIOUS — c4d2ccc4b547f2c14f6d581d9c4dd00090a5513bc64ae141198a6cdeb0279bdb is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (84/100). 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
c4d2ccc4b547f2c14f6d581d9c4dd00090a5513bc64ae141198a6cdeb0279bdb - SHA-1:
91af76a5dfd59b6cfc0170c0b4a1ff066f717e2d - MD5:
da6dbdc092a3d95cffa3f55ec61b8be5 - ssdeep:
1536:CsaF6dGPPQ2/b002XkxxEHNdwzjqBJWQngCMjgpkvgVuW8pO76spu:Vu/n356NdSjGgCygpk4Vt7a - TLSH:
T10838C0F3209BDC8CB347AF0769BA01A97087D7986132DB9180847A6CD47C9BDBF21591 - Submitted as: c4d2ccc4b547f2c14f6d581d9c4dd00090a5513bc64ae141198a6cdeb0279bdb
- File type: pdf · Size: 83935 bytes
- Verdict: malicious (84/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 84/100 is the fusion of 6 weighted signals:
- Embedded link rated malicious by URL analysis: http://holzbau-napetschnig.at/93494607754.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 14 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://resurrection-life.net/userfiles/files/vikevenadurofewamaz.pdf, https://tkquiz.com/userfiles/file/14602516095.pdf, https://3dreamvr.com/wp-content/plugins/super-forms/uploads/php/files/44f317a4d65511bcf99f283fb063d622/xemuvukokidedu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9674 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- desktop-hsgcbep._dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
9309ba9c5fb8217dc711d44eedd9eb0baf2b027d15270ebcfc9eb7b35965f56a - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\f3e1e7c3e93162de63db4a54b9d4a3d8.png -
b02e154bdc025b89b7423e63e2b62d9e482e07193236a7b4c7be7982658130ee - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/zMnd8XtcwSM/uplcv?utm_term=parliament+canteen+rate+list+2019+pdf
- http://resurrection-life.net/userfiles/files/vikevenadurofewamaz.pdf
- https://tkquiz.com/userfiles/file/14602516095.pdf
- https://3dreamvr.com/wp-content/plugins/super-forms/uploads/php/files/44f317a4d65511bcf99f283fb063d622/xemuvukokidedu.pdf
- http://gidaero.com/upload/fckeditor/file/beguzominebilerawew.pdf
- http://krajinar.cz/soubory/files/tinufibogomafeferara.pdf
- https://aihr-iadh.org/uploads/FCK_files/file/bikiserufozetiguzudigiwos.pdf
- https://shivajigrihnirman.com/singhania/downloads/file/xijumigi.pdf
- http://www.cascinasorigherio.it/wp-content/plugins/formcraft/file-upload/server/content/files/160b112bb1fe60---47362334951.pdf
- http://mlsy.cz/images/file/files/gifukavegiraragubitagevo.pdf
- http://holzbau-napetschnig.at/93494607754.pdf
- http://ahcxdq.com/uploads/file/020226474033.pdf
- http://doo-san.com/userfiles/file/20210817212115.pdf
- http://keletunderground.hu/images/uploaded_pics/file/wosuvos.pdf
- http://erfolgsapp.de/wp-content/plugins/formcraft/file-upload/server/content/files/160c508a1e4c3b---namifosu.pdf
- https://papiratisk.cz/soubory/wadogukixilidowakudan.pdf
- http://fvhs1970.com/clients/876770/File/kakupuvepet.pdf
- http://cetinelektrik.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/160c6ff0d6fbaf---1147971272.pdf
- http://reklama-kemerovo.ru/files/files/pilukugevewanaxugivapek.pdf
- https://eminenceconstruction.ca/viking1/uploads/files/kejalewutubozigomi.pdf
- http://aliancegroup.su/wp-content/plugins/formcraft/file-upload/server/content/files/16093e5ee4c9ac---zemifunevo.pdf
- http://www.cheapmotorcycleinsurancepa.com/wp-content/plugins/super-forms/uploads/php/files/07pd6prcmj24o1s1u6ppqf7o42/74832543206.pdf
- https://marblobathware.ph/app/webroot/img/files/wofegiwasetib.pdf
- http://maquinandoysubastando.com/dleyes/admin/fotos/file/mafomasoxosepera.pdf
- http://kystop.com/wp-content/plugins/super-forms/uploads/php/files/4g2ggokvr36rvvnnsua4kaf4g3/tedorene.pdf
Embedded domains
- feedproxy.google.com
- resurrection-life.net
- tkquiz.com
- 3dreamvr.com
- gidaero.com
- aihr-iadh.org
- shivajigrihnirman.com
- www.cascinasorigherio.it
- ahcxdq.com
- doo-san.com
- erfolgsapp.de
- fvhs1970.com
- reklama-kemerovo.ru
- eminenceconstruction.ca
- aliancegroup.su
- www.cheapmotorcycleinsurancepa.com
- maquinandoysubastando.com
- kystop.com
- poldercuptrofee.nl
- www.w3.org
- purl.org
- ns.adobe.com
- krajinar.cz
- mlsy.cz
- holzbau-napetschnig.at
Embedded IP addresses
- 172.172.255.217
- 52.110.12.2
- 4.230.171.124
- 20.42.179.192
- 74.178.76.54
- 135.232.92.137
- 52.123.128.14
- 40.99.133.226
- 72.145.35.102
- 203.26.79.13
- 74.179.71.159
- 20.184.175.18
- 4.150.223.109
- 52.168.112.67
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report