MALICIOUS — ca544c2ebf93a4f650623e360c0c40e40063e1bac69d477d6a442916ba2b70a1
MALICIOUS — ca544c2ebf93a4f650623e360c0c40e40063e1bac69d477d6a442916ba2b70a1 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
ca544c2ebf93a4f650623e360c0c40e40063e1bac69d477d6a442916ba2b70a1 - SHA-1:
3c05f3f2b73d3e85714c81b6a7e325b8fb045aae - MD5:
9ad6c78b9961d92c9bf72479089be9f0 - ssdeep:
1536:PkvTbAfgfTep0Pai7gWbChiZxYXcmt1RLrXTWQEcWCpOViriEkWAQnbYPQw33mhW:ObAfgSCy8gWvZxYzVrXToViriEkQbYWk - TLSH:
T11837CFF720ABCC4C774BEB4369A6116C745AE7CC6272DB9004C8B62C99BC67DAF10611 - Submitted as: ca544c2ebf93a4f650623e360c0c40e40063e1bac69d477d6a442916ba2b70a1
- File type: pdf · Size: 74135 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 13 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://chinatupai.com/web/js/ckfinder/userfiles/files/35719171425.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://qualityfirstservices.pro/testingsites/advantage_aviation/assets/media/file/dovorugonow.pdf, http://taaltoetsvo.nl/userfiles/file/bizofesamijodimawiriguv.pdf, http://poultech.net/d/files/jiwirabirabulazemu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9638 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787917283&P2=404&P3=2&P4=c32dwWczjY75D7%2fgduEa1vy0wp%2fyS8cPz9fKnll9Vx6H9xEw0bUi363LVhaXV%2fYdTXfglh8b8YhLbYEEvvaGIg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787917354&P2=404&P3=2&P4=UKhTUGKxJYczM5uSlJLtHb8%2bxwthSmtUSyN4SVai5f3A1tvfY%2f7Xw2uaqjE3cdPj2Ay4L%2fL7rKG0Lau7DBQgWw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- 151.101.30.172
- 23.11.37.157
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
67eaae7013ff9c4fcf9d2f025c418091afe079b12f7e4ff221185db3f4d2bb7a - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\17e9485b5eb4fb02d8a1e8cb2b2696ad.png -
ddace64eaaf8b5554f976e41def3935243691198182dda6274641669e6000bee - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/FevRqgeaUVY/uplcv?utm_term=how+to+hide+your+last+seen+on+whatsapp+android
- http://qualityfirstservices.pro/testingsites/advantage_aviation/assets/media/file/dovorugonow.pdf
- http://taaltoetsvo.nl/userfiles/file/bizofesamijodimawiriguv.pdf
- http://poultech.net/d/files/jiwirabirabulazemu.pdf
- http://www.prieteniitehnicii.ro/documente/file/pekolagapevuxum.pdf
- https://www.davidcosz.de/wp-content/plugins/super-forms/uploads/php/files/ql2qevilanonvt5c71op5r7gcn/87369717364.pdf
- https://leganordavigliana.it/uploads/file/31875079275.pdf
- http://shinaval.ru/userfiles/file/17465882785.pdf
- https://chinatupai.com/web/js/ckfinder/userfiles/files/35719171425.pdf
- http://soc-in.com/data/media/files/6144557023.pdf
- http://eaas-journal.org/survey/userfiles/files/90770080852.pdf
- http://kcpsystem.com/userData/board/file/vetadijoxetabaxovub.pdf
- http://isleford.com/filespath/files/20210905100235.pdf
- https://strechybenesov.cz/content/62298987655.pdf
- http://combatkuntao.com/ckeditor/ckfinder/userfiles/files/42408333231.pdf
- https://cheesykeju.com/contents/files/53700616847.pdf
- http://elskup.pl/images/assets/file/99076929291.pdf
- https://best-label.com/upload/files/12188672517.pdf
- https://swimproject.eu/wp-content/plugins/super-forms/uploads/php/files/9f14d7e1c35a31050d2efbe0aa7d8846/sakejojukojudupajisamox.pdf
- http://www.thebetterinsurance.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614cbdbe040bc---7797575004.pdf
- http://medicapoland.pl/uploaded/file/ravepivifafuwatogotar.pdf
- https://gemwares.com/userfiles/file/lodiw.pdf
- http://quickfix-poland.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613f5006695f1---vikejakigizedavi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- qualityfirstservices.pro
- taaltoetsvo.nl
- poultech.net
- www.davidcosz.de
- leganordavigliana.it
- shinaval.ru
- chinatupai.com
- soc-in.com
- eaas-journal.org
- kcpsystem.com
- isleford.com
- combatkuntao.com
- cheesykeju.com
- elskup.pl
- best-label.com
- swimproject.eu
- www.thebetterinsurance.com
- medicapoland.pl
- gemwares.com
- quickfix-poland.com
- www.w3.org
- purl.org
- ns.adobe.com
- www.prieteniitehnicii.ro
Embedded IP addresses
- 57.154.63.210
- 203.26.79.13
- 52.110.12.11
- 52.110.12.1
- 4.230.171.124
- 85.210.193.152
- 52.230.60.54
- 135.232.92.137
- 52.123.128.14
- 52.123.129.14
- 4.150.223.102
- 135.233.95.80
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report