MALICIOUS — d2da61d74a556979d5a90cf0988a2f8235f7f9f9e4f130b801442fcf35634128
MALICIOUS — d2da61d74a556979d5a90cf0988a2f8235f7f9f9e4f130b801442fcf35634128 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d2da61d74a556979d5a90cf0988a2f8235f7f9f9e4f130b801442fcf35634128 - SHA-1:
10770cdbcacc472d13a4cf457303d71e04a420cc - MD5:
6f08c8fce44a26bcd69dcffe0b48cf40 - ssdeep:
1536:z3swIK9Ff9wtm7O90IdWNLmlWNPjrma/rtogoWm0WUpO7xjW:ztB95mm7O9hdWNDr1JogoWS7Y - TLSH:
T14737C0F3226BDD5C7747DF43AAAB056CA4CAE7486161E9504084BA6CD07C9BDFF00A11 - Submitted as: d2da61d74a556979d5a90cf0988a2f8235f7f9f9e4f130b801442fcf35634128
- File type: pdf · Size: 70567 bytes
- Verdict: malicious (98/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://morard-mcf.fr/data/Files/pemufesosifipigoxivirufe.pdf, http://innova-perila.ru/upload/files/31972934571.pdf, http://saga.diamonds/uploads/ckfinder/files/furen.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 8 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1069 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep(3)._dosvc._tcp.local
- desktop-hsgcbep(4)._dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
- 20.190.167.64
- 52.168.117.174 US · Chantilly · AS8075 Microsoft Corporation
- 150.171.22.17
- 52.110.12.50 AU · Sydney · AS8075 Microsoft Corporation
- 52.110.12.16 AU · Sydney · AS8075 Microsoft Corporation
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/S30rS-6n6vg/uplcv?utm_term=build+react+native+android+app
- http://morard-mcf.fr/data/Files/pemufesosifipigoxivirufe.pdf
- http://innova-perila.ru/upload/files/31972934571.pdf
- http://saga.diamonds/uploads/ckfinder/files/furen.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/161457cb06abda---mowupe.pdf
- http://yanartextil.com/firma/files/91495023824.pdf
- http://www.hypnotiseur.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614e412315051---gofopoz.pdf
- http://www.sparkprototypes.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613a80a1bfcc5---79705884135.pdf
- https://betonwerkendejonge.nl/wp-content/plugins/formcraft/file-upload/server/content/files/161317c998b675---76734518306.pdf
- http://eventclub.pl/userfiles/file/77520803158.pdf
- http://www.fsnn.se/wp-content/plugins/formcraft/file-upload/server/content/files/1613f45f457ddc---zazopuxuleru.pdf
- https://pmeds.us/userfiles/file/64839832470.pdf
- http://indianspringhomes.net/userfiles/files/biwifojumexijajorofab.pdf
- https://chingchia.com/uploads/files/202109051807039118.pdf
- http://trenermichal.pl/wp-content/plugins/formcraft/file-upload/server/content/files/1614723b02ba5e---8746263227.pdf
- https://parklanehotel.asia/userfiles/file/73765547723.pdf
- http://www.sun-green.eu/ckfinder/userfiles/files/tulumuluwumigojeminele.pdf
- http://pspectr.ru/userfiles/file/rodilo.pdf
- http://traiteurluc.com/userfiles/file/84064550149.pdf
- http://mrukseo.pl/userfiles/file/52772653271.pdf
- https://gloriamus.org/Uploads/userfiles/files/46503209328.pdf
- http://fsnmmaterials.com/UPFILE/userfiles/files/wojupa.pdf
- http://hart-metale.pl/gimnazjum/userfiles/file/15164052383.pdf
- https://sydneystudytour.com/accounting/userfiles/file/10152278078.pdf
- http://coimbrasoftware.hu/images/uploads/files/saviladavipetozaxalo.pdf
Embedded domains
- feedproxy.google.com
- morard-mcf.fr
- innova-perila.ru
- www.1000ena.com
- yanartextil.com
- www.hypnotiseur.com
- www.sparkprototypes.com
- betonwerkendejonge.nl
- eventclub.pl
- www.fsnn.se
- pmeds.us
- indianspringhomes.net
- chingchia.com
- trenermichal.pl
- parklanehotel.asia
- www.sun-green.eu
- pspectr.ru
- traiteurluc.com
- mrukseo.pl
- gloriamus.org
- fsnmmaterials.com
- hart-metale.pl
- sydneystudytour.com
- www.w3.org
- purl.org
Embedded IP addresses
- 85.210.196.11
- 51.104.15.252
- 40.84.97.4
- 52.168.117.174
- 52.110.12.50
- 52.110.12.16
- 4.230.171.124
- 4.150.223.104
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report