MALICIOUS — 345549cf523e04155e47379deae7c4c683b970a7d5b5725ebc52828e32ed2cff
MALICIOUS — 345549cf523e04155e47379deae7c4c683b970a7d5b5725ebc52828e32ed2cff is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 3 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
345549cf523e04155e47379deae7c4c683b970a7d5b5725ebc52828e32ed2cff - SHA-1:
510e9a202c404ba34a22a5ab6833a72421d7a0a0 - MD5:
f1a0558899e392ad0a256a6d7e9ae33f - ssdeep:
1536:5+xZXva6BaN2xt39k6nD3pPDr1Bz8u4b769je2eHR7djyLBsZIc0GCPWOpOwrKWh:crv/Ba0xt3O6LpPn4u4b76feHRJjy6ZE - TLSH:
T1973AE1F30197DE4CBBCFCA02997F21AC548BE3D89162E864554CB75CA0BCAFC9811562 - Submitted as: 345549cf523e04155e47379deae7c4c683b970a7d5b5725ebc52828e32ed2cff
- File type: pdf · Size: 97345 bytes
- Verdict: malicious (98/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://2girlstrippin.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a40bc06e363---78248251529.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 10 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://cloudinfo01.smartevolve.com/images/ckeditor/files/72766967800.pdf, https://fotoprint.lv/downloads/file/41668396167.pdf, http://dieukhactransam.com/uploads/files/wafixomo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1180 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- ntp.ubuntu.com
- desktop-hsgcbep(2)._dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1KS0DP0cxss/uplcv?utm_term=abnormal+psychology+17th+edition+pdf+download
- http://cloudinfo01.smartevolve.com/images/ckeditor/files/72766967800.pdf
- https://fotoprint.lv/downloads/file/41668396167.pdf
- http://dieukhactransam.com/uploads/files/wafixomo.pdf
- http://gayaarchi.com/userfiles/file/20210804114435.pdf
- https://fptica.ru/images/file/16913832423.pdf
- http://botanicgardenscafe.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/160967fb94c4b3---60566648881.pdf
- https://www.accidentinjuryalbuquerque.com/wp-content/plugins/super-forms/uploads/php/files/7givvme3aa8nr747v4gfs8nvc6/85212276573.pdf
- http://www.driftime.ee/wp-content/plugins/formcraft/file-upload/server/content/files/160be140e516c3---xifidok.pdf
- http://2girlstrippin.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a40bc06e363---78248251529.pdf
- https://gamletaarnhuset.no/wp-content/plugins/formcraft/file-upload/server/content/files/160db75496abdc---kolituguj.pdf
- http://kazenergy.kz/wp-content/plugins/formcraft/file-upload/server/content/files/160835c28c6daa---30132438506.pdf
- http://grani-tonkogo-mira.ru/wp-content/plugins/super-forms/uploads/php/files/6586998255ad3695133a8547759c5c78/68763559998.pdf
- http://skrabl.pl/www/rpbd/fck/file/77267677776.pdf
- https://tonthephunglan.vn/upload/files/50168069933.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608eff31437dc---rewijejizofuleditas.pdf
- https://www.lindopoint.it/wp-content/plugins/super-forms/uploads/php/files/25ac5d63f2ebdd1e5e208cefbceccc52/figam.pdf
- https://givemeit.ru/wp-content/plugins/super-forms/uploads/php/files/8764b343e65d76eb2702d3d8080db0f3/wenakupirozuvabegipi.pdf
- https://ukdirectremovals.com/wp-content/plugins/super-forms/uploads/php/files/a03aac670e7a8ebecdd9ff078d35c550/jajinojajul.pdf
- https://staffxrecruitment.com/wp-content/plugins/super-forms/uploads/php/files/79938dbb10999a11e307dadb4be72c5d/widemukaketozomavanazuw.pdf
- http://la-roofers.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/16083950012226---wuteziza.pdf
- http://bdn10.cz/files/file/37458600857.pdf
- https://thepetrichortouch.com/wp-content/plugins/super-forms/uploads/php/files/ju7fma88ua0s1b5fpio3h8vvn8/34137182386.pdf
- http://edu-family72.ru/content/images/uploads/file/12115554741.pdf
- http://www.linkkorea.co.kr/wp-content/plugins/formcraft/file-upload/server/content/files/160721f85aa9df---16350264691.pdf
Embedded domains
- feedproxy.google.com
- cloudinfo01.smartevolve.com
- dieukhactransam.com
- gayaarchi.com
- fptica.ru
- botanicgardenscafe.com.au
- www.accidentinjuryalbuquerque.com
- 2girlstrippin.com
- gamletaarnhuset.no
- grani-tonkogo-mira.ru
- skrabl.pl
- www.1000ena.com
- www.lindopoint.it
- givemeit.ru
- ukdirectremovals.com
- staffxrecruitment.com
- la-roofers.co.uk
- thepetrichortouch.com
- edu-family72.ru
- www.linkkorea.co.kr
- leap-egypt.com
- fotoprint.lv
- www.driftime.ee
- kazenergy.kz
- tonthephunglan.vn
Embedded IP addresses
- 172.215.188.232
- 57.155.104.224
- 52.168.117.171
- 52.110.12.10
- 4.230.171.124
- 4.247.188.224
- 4.144.132.114
- 74.178.240.51
- 74.178.240.61
- 74.179.77.204
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report