MALICIOUS — dcdfad2c349449ccee9ea2fd394d5c03c17a82fdd0d771ec6bf48edb192cf46f
MALICIOUS — dcdfad2c349449ccee9ea2fd394d5c03c17a82fdd0d771ec6bf48edb192cf46f is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
dcdfad2c349449ccee9ea2fd394d5c03c17a82fdd0d771ec6bf48edb192cf46f - SHA-1:
2045cfcbfd5ee10592629a9a854d1adc565c3ccc - MD5:
a4677fb49ecb006e12f9cb6eeda970ba - ssdeep:
1536:99HuQAh5ZjpW27OApT3Su2EeNkGqNU8lqlBypDvFWapOtQHW2Ss8h9uiC58dP9hQ:GrHjpWMV32EeNkGkU8lqlBypD6tQ+fuF - TLSH:
T18A39D0F360E7DD8C769BEB0365AB119D904AA2895173FBA04148676CC4BC5FE3F24811 - Submitted as: dcdfad2c349449ccee9ea2fd394d5c03c17a82fdd0d771ec6bf48edb192cf46f
- File type: pdf · Size: 86305 bytes
- Verdict: malicious (95/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 17 external host(s) and 8 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://krisoc.ru/uplcv?utm_term=vr+games+ios, https://madspot.dk/ckfinder/userfiles/files/vapigoraninufekavobir.pdf, https://ppkh.net/userfiles/file/14093958810.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9684 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep._dosvc._tcp.local
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9?P1=1787945468&P2=404&P3=2&P4=A%2buH8UNFqs2x9a6K0MJdeJz13d5SPqy2VbFFkU6z9tHaCgdkTvo4a3KoVTpHWpVeLu%2b6emzts36p3pIQBvEflQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787945506&P2=404&P3=2&P4=NzFT4OCfBkNp0%2b8%2b%2f40yDw%2bVL%2bqMVPndvGUQ9A9ywMnvKs2US1zBA0CW6hl1sN36qxdxaks%2bNW154aelppyE%2fw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\fea533acdbc2a3e28aa5015769a1684d.png -
dd1132bc1cf3ae60e80d310fcd471d312cb04223072d0e99973e0e7f8afcc835 - C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
692b75341f3ae6c7bc8cf85e0501c746d90de30272901d85b268950e3ef04598 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://krisoc.ru/uplcv?utm_term=vr+games+ios
- https://madspot.dk/ckfinder/userfiles/files/vapigoraninufekavobir.pdf
- https://ppkh.net/userfiles/file/14093958810.pdf
- http://desushibar.com/userfiles/file/kufoligijamibuz.pdf
- http://counterreaction.net/wp-content/plugins/formcraft/file-upload/server/content/files/1614669f848a09---netarape.pdf
- http://hotel-ambassador-nice.com/upload/files/32612556591.pdf
- http://banglenhospital.com/UserFiles/File/molojagubamob.pdf
- https://bushregenerators.info/userfiles/files/92805317753.pdf
- https://fullprotec.com/ckfinder/userfiles/files/xidusaxigorosaviko.pdf
- http://sportservistocik.cz/UserFiles/File/33295590212.pdf
- http://az4group.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/161468e7a4b1ea---18870617739.pdf
- http://pocatellocampfire.com/wp-content/plugins/super-forms/uploads/php/files/62dcer8svd0uu1lp5n3tr36gks/femusi.pdf
- https://independentmusicleague.com/wp-content/plugins/super-forms/uploads/php/files/a0f765ba67b2fee3a2db8bda8f0e529c/pogozaporaniv.pdf
- http://avandcie-automation.com/ckfinder/userfiles/files/zifujagifawon.pdf
- http://vakantie-noordlimburg.nl/ckfinder/userfiles/files/kuxixeborowupabo.pdf
- https://dukeofmarshall.com/ckfinder/userfiles/files/43926682914.pdf
- http://mas.vacations/wp-content/plugins/formcraft/file-upload/server/content/files/16130c911da304---27663819930.pdf
- http://facilitymanagementassociates.com/survey/userfiles/files/71688723840.pdf
- http://architettoannalisatinelli.it/userfiles/files/77342214195.pdf
- http://istvietnam.com/rich_editor/file/libekazozowuj.pdf
- https://bestcaps99.com/ckfinder/userfiles/files/kepedenavufawez.pdf
- http://stihoplet.by/upload/editor/files/55303752988.pdf
- https://wcdt.co.th/wp-content/plugins/super-forms/uploads/php/files/b4u3l6q2usfoa2ri0leps6c8bo/8159144963.pdf
- http://studioingegneramato.com/userfiles/files/32372333581.pdf
- http://flixgolf.com/ckeditor/ckfinder/userfiles/files/xugujasoritufebog.pdf
Embedded domains
- krisoc.ru
- ppkh.net
- desushibar.com
- counterreaction.net
- hotel-ambassador-nice.com
- banglenhospital.com
- bushregenerators.info
- fullprotec.com
- az4group.com.br
- pocatellocampfire.com
- independentmusicleague.com
- avandcie-automation.com
- vakantie-noordlimburg.nl
- dukeofmarshall.com
- facilitymanagementassociates.com
- architettoannalisatinelli.it
- istvietnam.com
- bestcaps99.com
- studioingegneramato.com
- flixgolf.com
- ddmmaze.altruistictech.org
- saikunghouse.hk
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 20.184.175.3
- 52.123.252.232
- 20.247.184.197
- 52.110.12.48
- 4.230.171.124
- 135.232.92.137
- 20.76.201.171
- 40.103.64.242
- 135.232.92.34
- 52.123.129.14
- 203.26.79.13
- 52.123.252.239
- 57.155.104.224
- 40.79.163.155
- 48.199.12.1
- 20.50.201.204
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report