MALICIOUS — 266f8eea3860e9c236469fbc374084a898d71c8b114d7a07261a578635cb570b
MALICIOUS — 266f8eea3860e9c236469fbc374084a898d71c8b114d7a07261a578635cb570b is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 5 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
266f8eea3860e9c236469fbc374084a898d71c8b114d7a07261a578635cb570b - SHA-1:
e4c02b2da33e1e6f22642b244b9ee18127fd7cb8 - MD5:
844f9dfc1b8ed5d64e0b2cd8cf46eff5 - ssdeep:
1536:ZuYdI12gp8PBrC6t0VVUNXU6UCAk/SxWoQ4B9Dxfx7eZWw7/frUw0r:bxgePRC6q1RNDJYZre - TLSH:
T1D338BFF31197DC8DB6CB9F439DE720A4A45BC7886163EB914088AA6CC5AC1BDBF04940 - Submitted as: 266f8eea3860e9c236469fbc374084a898d71c8b114d7a07261a578635cb570b
- File type: pdf · Size: 79157 bytes
- Verdict: malicious (99/100)
Detections (5 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): Trojan-JADR!844F9DFC1B8E
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-JADR!844F9DFC1B8E (rule
Trojan-JADR!844F9DFC1B8E) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 9 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://slxiang.com/v15/Upload/file/202110201035365092.pdf, https://lasanisports.com/files/3570949614.pdf, https://expungemyrecordnj.com/wp-content/plugins/formcraft/file-upload/server/content/files/1615595c9884c1---wuxuzesopadug.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1078 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ntp.ubuntu.com
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- 23.40.52.85
- 23.11.37.157
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/Gsjc/~3/6Zflnl449io/uplcv?utm_term=how+to+recover+unsaved+slides+in+powerpoint
- http://slxiang.com/v15/Upload/file/202110201035365092.pdf
- https://lasanisports.com/files/3570949614.pdf
- https://expungemyrecordnj.com/wp-content/plugins/formcraft/file-upload/server/content/files/1615595c9884c1---wuxuzesopadug.pdf
- https://optimumquestsolutions.com/ckfinder/userfiles/files/13658332561.pdf
- https://adikketiga.com/contents/files/bufutegukewufe.pdf
- http://www.nuricomuvakfi.org/wp-content/plugins/super-forms/uploads/php/files/4c35mk778f40i8dmtv3nknh6a7/xobewupix.pdf
- http://m-styleauto.com/js/upload/files/suxomajapako.pdf
- http://www.barbazan-debat.fr/ckfinder/userfiles/files/43345509715.pdf
- https://nocnepal.org.np/ckfinder/userfiles/files/36626237336.pdf
- https://marksiegeldds.com/wp-content/plugins/super-forms/uploads/php/files/9b28a14d6135473eb5e22387d14b4b76/kukowufanupujijosejopexi.pdf
- http://alarcon-v.com/editor_upload_image/file/99864731262.pdf
- http://www.jcca.co.in/wp-content/plugins/formcraft/file-upload/server/content/files/1613044780d31c---17565352618.pdf
- https://ewt.cz/res/file/gavom.pdf
- https://jesssmithtri.com/jesssmith/ckfinder/userfiles/files/doposotabenepujubero.pdf
- https://ibshospitals.com/userfiles/file/11132743930.pdf
- https://gaseg.com/wp-content/plugins/super-forms/uploads/php/files/peebfn881mffjo2k907sirumbd/91751366612.pdf
- https://likeevent.it/writable/public/userfiles/file/29741921774.pdf
- https://ladychief.com/wp-content/plugins/super-forms/uploads/php/files/54b86e6aa1bb532b2fe4174e77edc041/1531053768.pdf
- http://st-johnson.com/Uploadfiles/files/devadefuka.pdf
- http://hstairan.com/fckeditor/editor/filemanager/connectors/php/userfiles/file/73300712429.pdf
- https://pmsp-me.com/userfiles/files/53487329794.pdf
- http://asiadomainstore.com/userfiles/file/rujunigeri.pdf
- http://vuoncotichdep.com/upload/files/buvujaretadonesetifuke.pdf
- https://ag-concept.ru/wp-content/plugins/super-forms/uploads/php/files/18905b4f6bfc4b0c483cb9b6cc9e3e7d/57249169609.pdf
Embedded domains
- feedproxy.google.com
- slxiang.com
- lasanisports.com
- expungemyrecordnj.com
- optimumquestsolutions.com
- adikketiga.com
- www.nuricomuvakfi.org
- m-styleauto.com
- www.barbazan-debat.fr
- marksiegeldds.com
- alarcon-v.com
- www.jcca.co.in
- jesssmithtri.com
- ibshospitals.com
- gaseg.com
- likeevent.it
- ladychief.com
- st-johnson.com
- hstairan.com
- pmsp-me.com
- asiadomainstore.com
- vuoncotichdep.com
- ag-concept.ru
- vatlieubaooncachnhiet.com
- ucinnovation.ru
Embedded IP addresses
- 20.42.179.192
- 52.168.117.174
- 4.247.188.233
- 52.110.12.53
- 4.230.171.124
- 52.253.84.76
- 20.184.175.5
- 74.178.240.61
- 72.153.5.62
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report