MALICIOUS — 163628915e4d6911bb8785c65558dcfa0ed92c9cd11c93de6f852400cd6e6454
MALICIOUS — 163628915e4d6911bb8785c65558dcfa0ed92c9cd11c93de6f852400cd6e6454 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100). 3 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
163628915e4d6911bb8785c65558dcfa0ed92c9cd11c93de6f852400cd6e6454 - SHA-1:
ff1f433b8776461667818f1f35ec28bcdc2bda1a - MD5:
0823e862174796d257d71e6c22bc5a91 - ssdeep:
1536:oY5MwZhdRVjftmNSRc2vuFUNxQFzWuYrIbdxwWQpOCXTF+5S0I:ewZTRVjFmstuFUfQFrhdxfCw54 - TLSH:
T13337C0F72097DE4C77579F036AA7126DA446D2886072DB60408CBB2C85BC9BDBF10960 - Submitted as: 163628915e4d6911bb8785c65558dcfa0ed92c9cd11c93de6f852400cd6e6454
- File type: pdf · Size: 74326 bytes
- Verdict: malicious (97/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 9 weighted signals:
- Embedded link rated malicious by URL analysis: http://test.uebersetzungen-nesselberger.de/wp-content/plugins/formcraft/file-upload/server/content/files/1614d46160c17c---modabuk.pdf - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 14 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://semangkamerah.com/contents/files/kejosurozatekiwoso.pdf, http://petra-koparki.pl/Upload/file/15481319352.pdf, http://yeosingol.com/FileData/ckfinder/files/20210903_9EED9013612B79F1.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
991 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep(3)._dosvc._tcp.local
- desktop-hsgcbep(4)._dosvc._tcp.local
- desktop-hsgcbep(5)._dosvc._tcp.local
- desktop-hsgcbep(6)._dosvc._tcp.local
- ntp.ubuntu.com
- _dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/LPIa9PGmDLg/uplcv?utm_term=armoury+crate+software+download
- https://semangkamerah.com/contents/files/kejosurozatekiwoso.pdf
- http://petra-koparki.pl/Upload/file/15481319352.pdf
- http://yeosingol.com/FileData/ckfinder/files/20210903_9EED9013612B79F1.pdf
- http://1day2night.com/UserFiles/file/49062575287.pdf
- https://halobysciton.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613df98fba375---bebitaxuz.pdf
- http://test.uebersetzungen-nesselberger.de/wp-content/plugins/formcraft/file-upload/server/content/files/1614d46160c17c---modabuk.pdf
- https://microfocus-realize2020mea.com/wp-content/plugins/super-forms/uploads/php/files/7405dbc0726207e40b677dd5a835b2c9/85105979710.pdf
- http://www.hzkontejnery.cz/ckfinder/userfiles/files/ximalepazazazuso.pdf
- http://colleges-in-tamilnadu.com/FCKeditor/userfiles/file/wevudenuxugi.pdf
- http://hotdeals24x7.com/ci/userfiles/files/37870734282.pdf
- https://acryl-bg.com/userfiles/file/22308110796.pdf
- https://kalitelivideoizle.com/resimler/files/fudaw.pdf
- http://sb555.com/photo/file/xotazegazulo.pdf
- https://kingwaterpure.com/ckfinder/userfiles/files/jumetekoxosewotasewewon.pdf
- http://art-lan.ru/uploads/assets/file/ruseteku.pdf
- http://xn--ob0bjxt9h99icicrvkksa421cwwp7hiv4d6a.com/ckfinder/userfiles/files/lexevuzenoto.pdf
- https://marksiegeldds.com/wp-content/plugins/super-forms/uploads/php/files/0796720f6defda32065546626284c88f/7324549514.pdf
- http://xinxinhouseware.com/uploadfile/files/vajan.pdf
- http://www.pilatesyoga.hr/files/files/34666114991.pdf
- http://khocabien.com/uploads/files/gizadesozowaruzo.pdf
- https://vietnaminsight.biz/ckfinder/userfiles/files/69188908347.pdf
- http://bioident.pl/photos_fck/file/sifuloferasuguruvekon.pdf
- http://www.sctiec.com/up_files/FCK/file/49237225970.pdf
- https://associazionebriciole.it/public/file/jopifekolape.pdf
Embedded domains
- feedproxy.google.com
- semangkamerah.com
- petra-koparki.pl
- yeosingol.com
- 1day2night.com
- halobysciton.com
- test.uebersetzungen-nesselberger.de
- microfocus-realize2020mea.com
- colleges-in-tamilnadu.com
- hotdeals24x7.com
- acryl-bg.com
- kalitelivideoizle.com
- sb555.com
- kingwaterpure.com
- art-lan.ru
- xn--ob0bjxt9h99icicrvkksa421cwwp7hiv4d6a.com
- marksiegeldds.com
- xinxinhouseware.com
- khocabien.com
- vietnaminsight.biz
- bioident.pl
- www.sctiec.com
- associazionebriciole.it
- www.w3.org
- purl.org
Embedded IP addresses
- 20.165.94.46
- 40.84.85.40
- 57.155.104.224
- 72.153.5.134
- 52.110.12.40
- 85.210.196.11
- 4.150.223.105
- 172.172.255.217
- 52.230.59.222
- 52.123.252.202
- 4.230.171.124
- 74.178.240.61
- 57.154.63.210
- 20.42.72.131
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report