MALICIOUS — 242f68638f7cfc3b52a4dddf00400a3ded67f7f859216cb1ab3a95ccfffd021f
MALICIOUS — 242f68638f7cfc3b52a4dddf00400a3ded67f7f859216cb1ab3a95ccfffd021f is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
242f68638f7cfc3b52a4dddf00400a3ded67f7f859216cb1ab3a95ccfffd021f - SHA-1:
50a1a1843faee471a2a6e72cc0422bc49f51f846 - MD5:
86e7784d6a51b88bea8cc7984d4380f9 - ssdeep:
1536:rdu6QriA68ranhKK7A359jncUlXGpiWh+9hxL+Cp6xLL7WJHUkw0wWQpOCyiad:psrV6/hKK78XjcUlWEWh/K6RLaHUkw0t - TLSH:
T1F738CFA32197DD5C769EEF07AAAB109C708AA7DC5162DB951088BA5CC53C0FEBF00611 - Submitted as: 242f68638f7cfc3b52a4dddf00400a3ded67f7f859216cb1ab3a95ccfffd021f
- File type: pdf · Size: 81137 bytes
- Verdict: malicious (99/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 7 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://vrindaindia.com/php/joseph/uploads/file/ramefudalufazujituxal.pdf, http://roland-toys.eu/userfiles/file/4706156004.pdf, https://www.zaantraining.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16156919770ef4---gujenofowufekotevudorogu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1013 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- 23.40.52.85
- 23.11.37.157
- 40.126.14.162
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/A3Ryygt5BCM/uplcv?utm_term=c+programming+and+data+structures+pdf
- https://vrindaindia.com/php/joseph/uploads/file/ramefudalufazujituxal.pdf
- http://roland-toys.eu/userfiles/file/4706156004.pdf
- https://www.zaantraining.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16156919770ef4---gujenofowufekotevudorogu.pdf
- http://artmetinc.com/wp-content/plugins/formcraft/file-upload/server/content/files/16146bca48b48e---53582797047.pdf
- http://harryreichert.de/uploaded_pics/News/file/turewatulilujudumil.pdf
- http://studiostocchi.eu/userfiles/files/23266017404.pdf
- https://wurstfargo.com/wp-content/plugins/super-forms/uploads/php/files/80e136cb66274e1a176ae51b04547807/karukofisudulubexebe.pdf
- https://www.singaporemedicalclinic.com/ckfinder/userfiles/files/dovujebufosenarizat.pdf
- http://bdn10.cz/files/file/lixeka.pdf
- http://getdol.com/page_data/file/83777274354.pdf
- http://telek-trans.hu/editor_up/92689980236.pdf
- https://excellencetogether.com/img/files/file/radafudetovevazumox.pdf
- http://daiichihr.com/uploads/news_file/30850101839.pdf
- http://j1ent.com/userfiles/file/20210905142316.pdf
- https://www.smartfutureexpo.com/ckfinder/userfiles/files/54742051815.pdf
- https://jager-ig.tw/up_photo/file/zomudoxex.pdf
- https://jogamiskolc.hu/ckfinder/userfiles/files/zunekapivegume.pdf
- http://www.emporiocaritaspisa.it/wordpress/wp-content/plugins/formcraft/file-upload/server/content/files/1615b38970ae2a---pokaxatofatamerevowag.pdf
- https://tapetcenter.ro/app/webroot/files/userfiles/files/tavidebame.pdf
- https://gpuhub.net/wp-content/plugins/super-forms/uploads/php/files/qeg8u1hkvr232u5qjqpp2ic090/88968739490.pdf
- http://sz-nuoyi.com/Upload/file/2021091616211036446.pdf
- https://mediaget.com/userfiles/files/farikixanip.pdf
- https://mywayrtk.com/userfiles/file/sunumujitus.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- vrindaindia.com
- roland-toys.eu
- www.zaantraining.nl
- artmetinc.com
- harryreichert.de
- studiostocchi.eu
- wurstfargo.com
- www.singaporemedicalclinic.com
- getdol.com
- excellencetogether.com
- daiichihr.com
- j1ent.com
- www.smartfutureexpo.com
- jager-ig.tw
- www.emporiocaritaspisa.it
- gpuhub.net
- sz-nuoyi.com
- mediaget.com
- mywayrtk.com
- www.w3.org
- purl.org
- ns.adobe.com
- bdn10.cz
- telek-trans.hu
Embedded IP addresses
- 20.247.184.142
- 52.110.12.37
- 4.230.171.124
- 40.84.97.4
- 72.153.5.96
- 4.150.223.103
- 4.207.44.69
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report