MALICIOUS — 12ab87b76df6781b92b17b7b722a645bf5619c94fd87deee935896c5e37d5f6a
MALICIOUS — 12ab87b76df6781b92b17b7b722a645bf5619c94fd87deee935896c5e37d5f6a is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
12ab87b76df6781b92b17b7b722a645bf5619c94fd87deee935896c5e37d5f6a - SHA-1:
824fda08d5a6335471654097e86666ae2b49d40f - MD5:
d0b709124e9675efca677d796c39705f - ssdeep:
1536:n0Jw+r60PCYAIKwKB/Ik7tiBG53wWY4wXDPbBw7m0fDJWiYvBRL4YT8UJ8HtNkcS:gwaPUIKw0p78BAtYrPNU8bLLwUajkcBY - TLSH:
T1D739D0F36097EC4C7A9EDF4759AB01AC6489D78C9271AA911488F73CC47C4BEAF00A51 - Submitted as: 12ab87b76df6781b92b17b7b722a645bf5619c94fd87deee935896c5e37d5f6a
- File type: pdf · Size: 92218 bytes
- Verdict: malicious (98/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://sin-hua.org/userfiles/46696872035.pdf, http://daegyung.kr/userfiles/file/20210912073013.pdf, http://khyljg.com/uploadfiles/files/51315750244.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 10 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in Acrobat.exe (pid 8240) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
993 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.85
- 23.11.37.157
- 40.126.14.163
- 52.230.60.54 SG · Singapore · AS8075 Microsoft Corporation
- 52.123.252.216 AU · Sydney · AS8075 Microsoft Corporation
- 23.33.238.178
- 23.198.40.44
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.173
- 23.33.238.114
- 20.42.73.31 US · Baltimore · AS8075 Microsoft Corporation
- 150.171.28.11
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/PmAiG5ZyT-k/uplcv?utm_term=mumu+app+player+pokemon+go
- http://sin-hua.org/userfiles/46696872035.pdf
- http://daegyung.kr/userfiles/file/20210912073013.pdf
- http://khyljg.com/uploadfiles/files/51315750244.pdf
- https://singhaniabrothersltd.com/ckeditor/ckfinder/userfiles/files/9408275664.pdf
- https://moolans.com/uploads/files/ninipujukonatuz.pdf
- https://pfollowers.com/ci/userfiles/files/59532892367.pdf
- https://svetplus.com/userfiles/files/fapejifevasawi.pdf
- https://www.ferienhof-schneider.de/wp-content/plugins/formcraft/file-upload/server/content/files/161336ba34fe92---refelitoranunizago.pdf
- http://ozhelalikram.de/resimler/files/78975247667.pdf
- http://lexxyin.net/files/fckeditor/file/xiluzuvakejexibuvodafe.pdf
- http://donghobaoan.com/uploads/files/69717631183.pdf
- https://mobilpetrol.olajpark.hu/files/files/97268510457.pdf
- https://kotypsy.pl/ckfinder/userfiles/files/vegozi.pdf
- http://ardechetendancebrut.fr/userfiles/ardechetendancebrut.fr/file/konotapetavewafi.pdf
- http://niezapominajkowo.eu/userfiles/file/38923960312.pdf
- http://vntattoosupply.net/uploads/image/files/48272232900.pdf
- http://mg001.cn/upload_fck/file/2021-9-11/20210911013600280518.pdf
- https://holyfamilyhospitals.com/ckfinder/userfiles/files/86734627547.pdf
- http://www.thunderesp.com/ckfinder/ckfinder.htmlfiles/lezes.pdf
- http://jikaramen.com/uploads/files/lozomagitanopubu.pdf
- http://bertrandetgastineaudesigners.com/userfiles/file/98566267940.pdf
- https://eternalbliss.net/file/xidojipoxi.pdf
- https://ist-lb1.istanajp.com/contents/files/22818192806.pdf
- https://yellowmangocafe.com/userfiles/file/xuxikog.pdf
Embedded domains
- feedproxy.google.com
- sin-hua.org
- daegyung.kr
- khyljg.com
- singhaniabrothersltd.com
- moolans.com
- pfollowers.com
- svetplus.com
- www.ferienhof-schneider.de
- ozhelalikram.de
- lexxyin.net
- donghobaoan.com
- kotypsy.pl
- ardechetendancebrut.fr
- niezapominajkowo.eu
- vntattoosupply.net
- mg001.cn
- holyfamilyhospitals.com
- www.thunderesp.com
- jikaramen.com
- bertrandetgastineaudesigners.com
- eternalbliss.net
- ist-lb1.istanajp.com
- yellowmangocafe.com
- sovaimm.it
Embedded IP addresses
- 20.42.73.28
- 4.150.223.106
- 4.150.223.100
- 20.184.175.16
- 52.230.60.54
- 52.123.252.216
- 4.230.171.124
- 20.42.73.31
- 85.210.196.11
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report