MALICIOUS — 0c49417e8e71ce582a60e5b31064b52835834b0b3ddea35aab791e53bbbd305a
MALICIOUS — 0c49417e8e71ce582a60e5b31064b52835834b0b3ddea35aab791e53bbbd305a is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 3 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0c49417e8e71ce582a60e5b31064b52835834b0b3ddea35aab791e53bbbd305a - SHA-1:
f428a407d3ceba1918a58ab7aebcfe8d4294ebc0 - MD5:
5d77f5c91c8a0c408f63a34230df8aec - ssdeep:
1536:wQIPhmQqGKtpj2Bh36VoCV4/+sut3kNO9nWTa3u1aD/iiWPO2FEmgLs4/:BIiG+Uh3Yoi4WsE3kNO9nW+lWQZ/ - TLSH:
T10B36D0E342A3DD0CF76E9B47FAA7526E51CBE3485065D6B0208C6729E06CA7F7D04A01 - Submitted as: 0c49417e8e71ce582a60e5b31064b52835834b0b3ddea35aab791e53bbbd305a
- File type: pdf · Size: 65536 bytes
- Verdict: malicious (98/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 14 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://www.inter-tube.co.uk/wp-content/plugins/super-forms/uploads/php/files/d08f0a89ec7fa8aa2c3b7c86f7cb2948/90716079323.pdf, https://otterdisplay.com/userfiles/file/kaviwoba.pdf, http://honghuibio.com/d/files/xefuz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1008 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- _dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- 23.40.52.85
- 23.11.37.157
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/Gsjc/~3/cmwvf4RlXg4/uplcv?utm_term=ram+bhakt+hanuman+katha+mp3+song+download
- https://www.inter-tube.co.uk/wp-content/plugins/super-forms/uploads/php/files/d08f0a89ec7fa8aa2c3b7c86f7cb2948/90716079323.pdf
- https://otterdisplay.com/userfiles/file/kaviwoba.pdf
- http://honghuibio.com/d/files/xefuz.pdf
- http://bulk-supplies.com/userfiles/file/13214299121.pdf
- http://aimic.com/userfiles/file/18627621643.pdf
- http://www.christinemartin.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1614796163ca83---juremiwejelepogugedasaget.pdf
- https://paramourpourbebe.bettygagne.ca/userfiles/file/80890156685.pdf
- https://ecosolar-energy.com/piceditor/file/waxuresubewoluv.pdf
- https://californiaoptionsrealestate.com/wp-content/plugins/super-forms/uploads/php/files/91a315012693ada5f136f793888f3eaa/lirubewogirut.pdf
- http://sotel-perm.ru/site/file/fimevisirimivovumukewe.pdf
- http://yuhongzg.com/d/files/53729298355.pdf
- http://sh-ruiyangcpa.com/userfiles/file/2021-10///20211022028457166.pdf
- http://vtvxm.vn/userfiles/file/vabosoxoloduforigubemozog.pdf
- http://nato-denkmal.de/uploads/file/tiraguzivuze.pdf
- http://www.appsolutely.sg/wp-content/plugins/formcraft/file-upload/server/content/files/1614242192df0c---togadizawakifi.pdf
- https://kindeeyudee.com/ck_files/files/99855803631.pdf
- https://spherule.org/wp-content/plugins/super-forms/uploads/php/files/sq577g66slai76ud6tv30q9tj7/31126800080.pdf
- http://yds-wcv.jp/free_images/files/64071550719.pdf
- http://casavacanzesanvito.eu/userfiles/files/7348727382.pdf
- https://xn--fct5g39pjpo.tw/upload/leakstop/files/bidaxasol.pdf
- https://www.havanasalsa-dance-tours.com/wp-content/plugins/super-forms/uploads/php/files/34cb81328e8f6f0fb60df6ef41df7796/92010335805.pdf
- http://md-servicios.com/userfiles/file/ninejulo.pdf
- http://jarosi.hu/files/file/wozakuwu.pdf
- https://theloneranger.tv/clients/loneranger/ckfinder/userfiles/files/libawetexekela.pdf
Embedded domains
- feedproxy.google.com
- www.inter-tube.co.uk
- otterdisplay.com
- honghuibio.com
- bulk-supplies.com
- aimic.com
- www.christinemartin.co.uk
- paramourpourbebe.bettygagne.ca
- ecosolar-energy.com
- californiaoptionsrealestate.com
- sotel-perm.ru
- yuhongzg.com
- sh-ruiyangcpa.com
- nato-denkmal.de
- www.appsolutely.sg
- kindeeyudee.com
- spherule.org
- yds-wcv.jp
- casavacanzesanvito.eu
- xn--fct5g39pjpo.tw
- www.havanasalsa-dance-tours.com
- md-servicios.com
- theloneranger.tv
- vtvxm.vn
- jarosi.hu
Embedded IP addresses
- 85.210.196.11
- 172.172.255.217
- 20.42.179.192
- 172.172.255.218
- 57.154.63.210
- 162.159.142.9
- 52.123.252.235
- 52.110.12.54
- 4.230.171.124
- 172.64.154.167
- 52.253.84.76
- 4.207.44.71
- 135.232.92.137
- 20.42.73.24
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report