MALICIOUS — 05906d63819dc9d5094c2a1bc1860bffdddbfa1f8f42cf7f1f0badf9164f2332
MALICIOUS — 05906d63819dc9d5094c2a1bc1860bffdddbfa1f8f42cf7f1f0badf9164f2332 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
05906d63819dc9d5094c2a1bc1860bffdddbfa1f8f42cf7f1f0badf9164f2332 - SHA-1:
7b47c74ff75cf6f4d12d8e6e92992680d8799323 - MD5:
684470aa8fe82cd71d0cf12cc8309b82 - ssdeep:
1536:Ha1RX2wbbdFH5tdtnzEAVLlpH0xgHgWaXsiddDPmWxApOGIHGQ0d9VA:62wbbbZNnzEAVLlppHSXld9z3Gcx0dc - TLSH:
T10738D1F32067DE0C725BDB0365DB12ADB48AE7CC2662DE600188B75CC57C9BDBA10961 - Submitted as: 05906d63819dc9d5094c2a1bc1860bffdddbfa1f8f42cf7f1f0badf9164f2332
- File type: pdf · Size: 84039 bytes
- Verdict: malicious (99/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 10 external host(s) and 48 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://rlmahtani.com/userfiles/files/76202650320.pdf, https://ocvirapuato.com.mx/wp-content/plugins/super-forms/uploads/php/files/25fb123573d834ce51c1523295dc6706/regowufipubujawozex.pdf, https://samyenngochoang.com/wp-content/plugins/super-forms/uploads/php/files/of80vc1gm66fubg8kk8v17cppu/boxuvemit.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1041 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- _http._tcp.security.ubuntu.com
- _http._tcp.archive.ubuntu.com
- archive.ubuntu.com
- security.ubuntu.com
- _https._tcp.motd.ubuntu.com
- motd.ubuntu.com
- _https._tcp.esm.ubuntu.com
- esm.ubuntu.com
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/DOqCt-cVA4I/uplcv?utm_term=prepositions+of+place+exercises+with+pictures+pdf
- https://rlmahtani.com/userfiles/files/76202650320.pdf
- https://ocvirapuato.com.mx/wp-content/plugins/super-forms/uploads/php/files/25fb123573d834ce51c1523295dc6706/regowufipubujawozex.pdf
- https://samyenngochoang.com/wp-content/plugins/super-forms/uploads/php/files/of80vc1gm66fubg8kk8v17cppu/boxuvemit.pdf
- http://fonnepal.org/userfiles/file/3755231213.pdf
- http://agisma.ru/files/pages/files/62615220689.pdf
- http://law885995.com/upload/fckimages/file/64316609629.pdf
- http://www.cenlaenvironmental.com/siteuploads/editorimg/file/bivitofaxuluxejutubev.pdf
- http://arcomproltd.com/userfiles/file/66981975705.pdf
- https://wecafephuket.com/wp-content/plugins/super-forms/uploads/php/files/ugbhvu7bfci52cfosee2e8rjl9/42181186574.pdf
- http://ebslang.net/_UploadFile/Images/file/66197629783.pdf
- http://om-ar.com/userfiles/file/refev.pdf
- http://fslawoffice.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/97441917835.pdf
- http://come2menorca.com/images/file/92414191765.pdf
- https://www.tifdip.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608e5a6357df4---79114594771.pdf
- https://marksiegeldds.com/wp-content/plugins/super-forms/uploads/php/files/6e531401e0e2b0e174e8182bf66c16ba/36013454523.pdf
- http://www.consorcio.edu.pe/wp-content/plugins/formcraft/file-upload/server/content/files/161258f84463ce---73876968710.pdf
- http://www.sunaryem.com.tr/wp-content/plugins/super-forms/uploads/php/files/ls3ukrevjn58iilgng39g5jv81/nuzerimumumumale.pdf
- https://baodinhsolar.com/wp-content/plugins/super-forms/uploads/php/files/gt6pscpv1176faa9fg9sadinj1/lofas.pdf
- https://pfgmm.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/160a4dff0c36ac---97011771265.pdf
- https://palcev.ru/userfiles/file/67361902248.pdf
- https://miguktour.com/FileData/ckfinder/files/20210621_07F4781347FDF19B.pdf
- http://pebyte.com/wp-content/plugins/super-forms/uploads/php/files/hlol846d94pqloser87sfkqrnk/46421814029.pdf
- https://samiznojmo.cz/wp-content/plugins/super-forms/uploads/php/files/b109aa72f53613a71cf1255bfab394dd/bidalomunow.pdf
- http://adhdadvisory.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a6cb670dc73---41590951098.pdf
Embedded domains
- feedproxy.google.com
- rlmahtani.com
- ocvirapuato.com.mx
- samyenngochoang.com
- fonnepal.org
- agisma.ru
- law885995.com
- www.cenlaenvironmental.com
- arcomproltd.com
- wecafephuket.com
- ebslang.net
- om-ar.com
- fslawoffice.com
- come2menorca.com
- www.tifdip.com
- marksiegeldds.com
- baodinhsolar.com
- pfgmm.com.au
- palcev.ru
- miguktour.com
- pebyte.com
- adhdadvisory.com
- genia-groupe.fr
- sdes.in
- www.w3.org
Embedded IP addresses
- 54.154.251.197
- 3.254.173.149
- 104.20.28.246
- 172.66.152.176
- 172.172.255.218
- 13.69.116.107
- 20.247.185.124
- 52.123.252.231
- 52.110.12.19
- 4.230.171.124
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report