MALICIOUS — 305804ba7a8cfd30beb25d88dca2873f6ee81e52d2cfb85c15777744bbae6f61
MALICIOUS — 305804ba7a8cfd30beb25d88dca2873f6ee81e52d2cfb85c15777744bbae6f61 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100). 5 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
305804ba7a8cfd30beb25d88dca2873f6ee81e52d2cfb85c15777744bbae6f61 - SHA-1:
2436218aa0aafb4ec24dcf8aedd07ed2891c58c1 - MD5:
5e9921b5a25f8917be7128eebd5d93b6 - ssdeep:
1536:3IGY6+S3Lu0oUwqBdQs0gD2pXT+UhOYgjAlsKjWUXj2hR2CAM:HWSe4BdQs0v/gjAuiXj2hRd - TLSH:
T17738CFF360E7DD8C3A9B5F137EA2289D648DD3886432E790444C765CD47CAADBE12A10 - Submitted as: 305804ba7a8cfd30beb25d88dca2873f6ee81e52d2cfb85c15777744bbae6f61
- File type: pdf · Size: 78101 bytes
- Verdict: malicious (100/100)
Detections (5 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!5E9921B5A25F
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4455642/normal_5fc59acb2090c.pdf - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PDF/Phish-FAB!5E9921B5A25F (rule
PDF/Phish-FAB!5E9921B5A25F) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://jottigo.ru/strik?utm_term=audio+converter+offline+apk, https://cdn-cms.f-static.net/uploads/4455670/normal_603b42d3518f3.pdf, https://static.s123-cdn-static.com/uploads/4455642/normal_5fc59acb2090c.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 9 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1031 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.85
- 23.11.37.157
- 142.251.42.110
- 104.46.162.224 AU · Melbourne · AS8075 Microsoft Corporation
- 85.210.193.152 GB · AS8075 MICROSOFT-MAINT
- 20.190.167.18
- 52.123.252.234 AU · Sydney · AS8075 Microsoft Corporation
- 4.144.132.223 SG · Singapore · AS8075 Microsoft Corporation
- 52.110.12.26 AU · Sydney · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.209
- 192.168.122.108
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://jottigo.ru/strik?utm_term=audio+converter+offline+apk
- https://cdn-cms.f-static.net/uploads/4455670/normal_603b42d3518f3.pdf
- https://static.s123-cdn-static.com/uploads/4455642/normal_5fc59acb2090c.pdf
- https://static.s123-cdn-static.com/uploads/4481052/normal_5fecad802a690.pdf
- https://static.s123-cdn-static-d.com/uploads/4459034/normal_60afe62294f30.pdf
- https://cdn-cms.f-static.net/uploads/4392867/normal_606d573c49259.pdf
- https://static.s123-cdn-static.com/uploads/4473445/normal_600662a42f0f0.pdf
- https://cdn-cms.f-static.net/uploads/4473902/normal_5fdace605f34b.pdf
- https://cdn-cms.f-static.net/uploads/4369327/normal_605a060a08090.pdf
- https://uploads.strikinglycdn.com/files/c4c907e5-5201-4737-8ace-5eb0a56a1d8f/diono_radian_3r_vs_3rxt.pdf
- https://cdn-cms.f-static.net/uploads/4446377/normal_5fe82d64659f8.pdf
- https://uploads.strikinglycdn.com/files/2e7f77eb-68f7-45b8-a467-b03610a3cea4/musuxudunutefevu.pdf
- https://static.s123-cdn-static.com/uploads/4418367/normal_5ffc1a78266c3.pdf
- https://cdn-cms.f-static.net/uploads/4500432/normal_5fd7f8aa37d87.pdf
- https://fifejinokufo.weebly.com/uploads/1/3/4/8/134846395/333bdb4c98c0f28.pdf
- https://uploads.strikinglycdn.com/files/efdd117c-6f20-4b6e-a868-aa08a4dbbc18/3776665251.pdf
- https://uploads.strikinglycdn.com/files/f8d33af4-db2b-47c9-96f0-6d06e9e139ac/mouse_guard_roleplaying_game_box_set_2nd_ed.pdf
- https://static.s123-cdn-static-d.com/uploads/4455657/normal_60b13e44a46d5.pdf
- https://panodetis.weebly.com/uploads/1/3/4/6/134669877/fukirivawadujafuku.pdf
- https://cdn-cms.f-static.net/uploads/4388424/normal_5fd793c660b9a.pdf
- https://cdn-cms.f-static.net/uploads/4527357/normal_603d5f49ca1bc.pdf
- https://static.s123-cdn-static.com/uploads/4408712/normal_5fde8c6918ebc.pdf
- https://didipovewefof.weebly.com/uploads/1/3/4/3/134306756/betiduripobe.pdf
- https://cdn-cms.f-static.net/uploads/4480148/normal_6031abe7d0eb7.pdf
- https://xadebunurag.weebly.com/uploads/1/3/1/4/131454816/furowawuxuk.pdf
Embedded domains
- jottigo.ru
- cdn-cms.f-static.net
- static.s123-cdn-static.com
- static.s123-cdn-static-d.com
- uploads.strikinglycdn.com
- fifejinokufo.weebly.com
- panodetis.weebly.com
- didipovewefof.weebly.com
- xadebunurag.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 104.46.162.224
- 85.210.193.152
- 52.123.252.234
- 4.144.132.223
- 52.110.12.26
- 4.230.171.124
- 13.69.109.131
- 20.184.175.6
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report