MALICIOUS — fa55301d83978e4ee0775e12d845b9ae501469cf92406f2e1f0f13981effae5d
MALICIOUS — fa55301d83978e4ee0775e12d845b9ae501469cf92406f2e1f0f13981effae5d is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
fa55301d83978e4ee0775e12d845b9ae501469cf92406f2e1f0f13981effae5d - SHA-1:
24119a7835850771417a4f4255ddb51b5194f856 - MD5:
bd18aa40197715da0ab0ed0a4835f1d8 - ssdeep:
1536:83yQfVRvXS8/ak2t1D/Y2uTcJj0HcZWkNpOPaWwb3dW9frev8Sf2IWA:RQtdXNSky/gTi0HcCPANWhrekji - TLSH:
T1A538CFF361D7DE9D3B579B0376E702586086E3C86522AB4001C8B72CC5BC9BEBB50661 - Submitted as: fa55301d83978e4ee0775e12d845b9ae501469cf92406f2e1f0f13981effae5d
- File type: pdf · Size: 83050 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://xn--pssa17sw71b.tw/upimages/files/kirawonesixavavo.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 17 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://mk-sito.it/uploads/file/52427675223.pdf, http://sm300159.agchost.com/userfiles/files/12733811959.pdf, http://cen7dias.es/userfiles/files/pefezibesevelalusapodibut.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9668 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- _dosvc._tcp.local
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787858477&P2=404&P3=2&P4=K4IjmjHylFCRc0JwWdYRfZZISA5F518cfRJ%2fvGMfhopc8U%2fshSMqABLGA4nbNb8ROH7Y3t5SWp%2bwOt17tiENgw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787858500&P2=404&P3=2&P4=OM%2fNcf4njQV81W3BDgy6Vv0IsPh5y8owLufKbKLTzlrSQF73dOzl7i6FJXsDX0l8mqgRBLHl7rP%2bRviJO9WD0w%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
0f955a2b7ec9a5bcc20851d4be577f10fac04e7695aeb6b01846e4170001f936 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\d68b511b47a2ad02928944adc6ce19e1.png -
b19e7b6bc7eb631245ef6b84bdf2e333e553fa6434f0fc178881f220ddf77b84 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/1KS0DP0cxss/uplcv?utm_term=how+to+see+pictures+on+instagram+without+account
- https://mk-sito.it/uploads/file/52427675223.pdf
- http://sm300159.agchost.com/userfiles/files/12733811959.pdf
- http://cen7dias.es/userfiles/files/pefezibesevelalusapodibut.pdf
- https://communeouchamps.fr/userfiles/file/79986596099.pdf
- https://paidionresearch.com/userfiles/files/poxevi.pdf
- https://loyallcanada.ca/editor_files/file/75972762942.pdf
- https://network-italia.it/file/77806677105.pdf
- http://ovstav.cz/app/webroot/files/files/57520229282.pdf
- https://xn--pssa17sw71b.tw/upimages/files/kirawonesixavavo.pdf
- http://17njl.com/userfiles/files/musonara.pdf
- http://www.dawnrotaryclub.tw/UserFiles/files/voxuxob.pdf
- http://artiguardia.pl/userfiles/file/tebamar.pdf
- https://cincia.ro/ckfinder/userfiles/files/31489307287.pdf
- https://grandegroup.net/files/15853392595.pdf
- http://averon.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16134a75c3e499---midisutozonus.pdf
- https://danfort.lv/userfiles/file/gumomufisuz.pdf
- http://balalajka.nu/media/16958000302.pdf
- https://glasschneider.koeln/wp-content/plugins/super-forms/uploads/php/files/jk7sqomg4mah17v38vspg1ptkp/97621454425.pdf
- https://divorcioconsensual.com.br/wp-content/plugins/super-forms/uploads/php/files/8df88a8dec0b1e7d9a005ace1e843e4c/pufafapatimuv.pdf
- http://csa.china-led.net/static/editor/ckeditor/ckfinder/upfile/files/84379592589.pdf
- https://austdoorcaocap.com/upload/files/25093290999.pdf
- http://salocchi.it/userfiles/files/55588301804.pdf
- https://chingchia.com/uploads/files/202109020917111646.pdf
- https://koltoztetes-szallitas-lomtalanitas.excore.hu/ckfinder/userfiles/files/61281602257.pdf
Embedded domains
- feedproxy.google.com
- mk-sito.it
- sm300159.agchost.com
- cen7dias.es
- communeouchamps.fr
- paidionresearch.com
- loyallcanada.ca
- network-italia.it
- xn--pssa17sw71b.tw
- 17njl.com
- www.dawnrotaryclub.tw
- artiguardia.pl
- grandegroup.net
- averon.ca
- divorcioconsensual.com.br
- csa.china-led.net
- austdoorcaocap.com
- salocchi.it
- chingchia.com
- www.w3.org
- purl.org
- ns.adobe.com
- ovstav.cz
- cincia.ro
- danfort.lv
Embedded IP addresses
- 4.247.188.233
- 52.123.252.245
- 52.110.12.15
- 4.230.171.124
- 20.247.184.197
- 20.165.94.63
- 74.178.240.51
- 74.178.240.61
- 52.123.128.14
- 135.233.45.222
- 72.145.35.102
- 203.26.79.13
- 135.232.92.34
- 92.223.78.30
- 57.154.63.210
- 172.170.180.133
- 20.42.65.93
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report