MALICIOUS — 1754e03f6dc73161349b3ca750980d0819671c1f3eab85c53a74dbe4c2ce723a
MALICIOUS — 1754e03f6dc73161349b3ca750980d0819671c1f3eab85c53a74dbe4c2ce723a is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1754e03f6dc73161349b3ca750980d0819671c1f3eab85c53a74dbe4c2ce723a - SHA-1:
a1d723a55ca8946057e09d36f3c90c9d0ac47f5e - MD5:
e71174ae994fc052f3aab364d85b2eba - ssdeep:
1536:YdfQ21XuQ8RmcXdxGavQNVTCULA+hCBzyOdbCL3QESN5LmWCpOVi3nP521zWLpxM:0pXuQmmcNMavQlLA+hCJbPESNNVi3nPU - TLSH:
T1F939D0F321DBDD0C7747AB4328FA0299E48BD6886261E7A00588F66CC57C9BE7F10951 - Submitted as: 1754e03f6dc73161349b3ca750980d0819671c1f3eab85c53a74dbe4c2ce723a
- File type: pdf · Size: 87566 bytes
- Verdict: malicious (99/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 9 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://nd-58.ru/wp-content/plugins/super-forms/uploads/php/files/676bf91d8252ffbaa8e0a57005dddef3/16598521739.pdf, http://thingsantiquesla.com/userfiles/files/23961556686.pdf, https://smarttactic.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1607bfca797ce2---fejililikot.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1154 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ntp.ubuntu.com
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- 23.40.52.209
- 23.11.37.157
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/3vuEKuznOb8/uplcv?utm_term=math+textbook+grade+6+nelson
- http://nd-58.ru/wp-content/plugins/super-forms/uploads/php/files/676bf91d8252ffbaa8e0a57005dddef3/16598521739.pdf
- http://thingsantiquesla.com/userfiles/files/23961556686.pdf
- https://smarttactic.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1607bfca797ce2---fejililikot.pdf
- http://phamtrangia.com/upload/files/91202199498.pdf
- https://goactive.hu/wp-content/plugins/super-forms/uploads/php/files/a60475b369c455be45ab061ab56a96a2/daduxuvuv.pdf
- http://artetendasud.it/userfiles/files/39313503165.pdf
- https://eastmangroupllc.net/ckfinder/userfiles/files/watofaxisi.pdf
- http://mdsalon.ru/img/lib/file/17763382600.pdf
- http://montpellier-business-plan.eu/mbp/upload/images/images/upload/ckfinder/xusakevafafo.pdf
- https://grand-forge.ru/wp-content/plugins/super-forms/uploads/php/files/e9cdb19b9e8bfd9bcf537f2097e68fbf/fisidojokuxalokabiwexinid.pdf
- http://gmei.lt/ckfinder/userfiles/files/rinodojupaburevujasat.pdf
- https://kes-stv.ru/wp-content/plugins/super-forms/uploads/php/files/8e66b41af0e4a38101e841d2c1d760d7/kosutawaminelozujawafofe.pdf
- http://consade.com/userfiles/file/2985832120.pdf
- http://abwmechanicsville.com/uploads/files/xolofenetijudiz.pdf
- http://sgyscom.com/upload_fck/file/2021-7-5/20210705181635118897.pdf
- http://superbarter.sk/media/file/44982725758.pdf
- https://kopari.hu/files/file/nivukujiguvap.pdf
- https://playgametoday.ru/wp-content/plugins/super-forms/uploads/php/files/74452c9a3b0aea422137bc6c6f6aa1fc/xadakeb.pdf
- http://monktonlionsclubkidscamp.com/clients/9/99/99b8b5517e5fb663501b7ee5137ebf55/File/82728142330.pdf
- https://cuisinescartier.ca/upload/editor/file/16777001257.pdf
- http://nhaphangmy.us/upload/files/58346094950.pdf
- http://kuresi-kaitori.com/upload/content_pic/files/vimofukofoni.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- nd-58.ru
- thingsantiquesla.com
- phamtrangia.com
- artetendasud.it
- eastmangroupllc.net
- mdsalon.ru
- montpellier-business-plan.eu
- grand-forge.ru
- kes-stv.ru
- consade.com
- abwmechanicsville.com
- sgyscom.com
- playgametoday.ru
- monktonlionsclubkidscamp.com
- cuisinescartier.ca
- nhaphangmy.us
- kuresi-kaitori.com
- www.w3.org
- purl.org
- ns.adobe.com
- smarttactic.ro
- goactive.hu
- gmei.lt
- superbarter.sk
Embedded IP addresses
- 172.66.2.5
- 4.144.132.223
- 52.110.12.4
- 4.230.171.124
- 4.207.44.77
- 74.178.76.128
- 57.154.63.210
- 72.153.5.141
- 52.168.117.168
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report