MALICIOUS — 3729fb66ce0385a3eb6d6b9bb3cbf728f83b823dce2b2b88d436ec989e84e6d6
MALICIOUS — 3729fb66ce0385a3eb6d6b9bb3cbf728f83b823dce2b2b88d436ec989e84e6d6 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3729fb66ce0385a3eb6d6b9bb3cbf728f83b823dce2b2b88d436ec989e84e6d6 - SHA-1:
2cf07a2aee3049fd3db7f6883806328e946579a7 - MD5:
de2992da6a88a3c9464bb0114625c798 - ssdeep:
1536:OZYtmIHHMBPcm/gNeHn0h73byUhrJG6rb6wa7sFs15DzgHNDQ+F:NtmIHHMBUmCVJB36O8DzgFQe - TLSH:
T18B36D0D160A3EE4CBA8F1F827BA671BE4989F34C9061E2A1024C5F2D906C56F3C5459B - Submitted as: 3729fb66ce0385a3eb6d6b9bb3cbf728f83b823dce2b2b88d436ec989e84e6d6
- File type: pdf · Size: 69404 bytes
- Verdict: malicious (98/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Trellix Stinger (McAfee): PDF/Phish-FAB!DE2992DA6A88
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Trellix Stinger (McAfee) flagged PDF/Phish-FAB!DE2992DA6A88 (rule
PDF/Phish-FAB!DE2992DA6A88) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://midufefew.ru/strik?utm_term=wd+tv+hd+media+player+alternatives, https://cdn-cms.f-static.net/uploads/4460045/normal_6068e9d57ce83.pdf, https://static.s123-cdn-static.com/uploads/4460975/normal_5fc96a8ed914a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 9 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in Acrobat.exe (pid 7448) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
1076 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.85
- 23.11.37.157
- 172.66.2.5 US · San Francisco · AS13335 Cloudflare, Inc.
- 20.190.167.66
- 52.253.84.76 SG · Singapore · AS8075 Microsoft Corporation
- 150.171.22.17
- 23.198.40.44
- 52.110.12.44 AU · Sydney · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.110
- 40.84.85.40 US · Boydton · AS8075 Microsoft Corporation
- 4.150.223.99 US · Des Moines · AS8075 Microsoft Corporation
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://midufefew.ru/strik?utm_term=wd+tv+hd+media+player+alternatives
- https://cdn-cms.f-static.net/uploads/4460045/normal_6068e9d57ce83.pdf
- https://static.s123-cdn-static.com/uploads/4460975/normal_5fc96a8ed914a.pdf
- http://limixawur.rf.gd/16234907757.pdf
- http://shop-onlain.fun/wenzel_monarch_tent_instructionsmr4g3.pdf
- https://uploads.strikinglycdn.com/files/723b495b-6222-41c3-b819-4250af259bf9/wurebizemimi.pdf
- https://cdn.sqhk.co/muruwake/hcgdEEM/journal_el_khabar_d_aujourd_hui.pdf
- https://cdn-cms.f-static.net/uploads/4426688/normal_5fd27158a2b1e.pdf
- http://pugetuwozijeso.rf.gd/introduction_to_sociology_anthony_giddens_free_download.pdf
- https://uploads.strikinglycdn.com/files/ee17ca90-9ce0-4f7d-a379-7a9a8248328f/76478933291.pdf
- http://ludodugadigepez.rf.gd/zepifisaxefini.pdf
- https://cdn-cms.f-static.net/uploads/4490974/normal_603b97c7ca04f.pdf
- http://rifimakegezibor.22web.org/domizuzanefene.pdf
- https://cdn.sqhk.co/ponesigis/zhhLrja/liverpool_latest_transfer_news_update_today.pdf
- https://cdn.sqhk.co/pubamegumox/whcgchi/spider_solitaire_card_game_free_online_aarp.pdf
- https://uploads.strikinglycdn.com/files/3a8af7b7-5aa9-471b-8fe9-c5ee776b29fb/138_longwood_lake_road_oak_ridge_nj.pdf
- https://cdn.sqhk.co/mixaluwekitu/hilijAQ/susuxetubolamodifewom.pdf
- http://reduslim-buy.site/39035223657xwgzi.pdf
- https://static.s123-cdn-static.com/uploads/4393180/normal_5fe3fbe2ed800.pdf
- http://slmit.fun/iot_farming_applications8l74i.pdf
- https://cdn.sqhk.co/givikofuf/bWmlhaH/banufavatolebosifixadeb.pdf
- http://fimewot.xyz/277261129601fdce.pdf
- https://cdn-cms.f-static.net/uploads/4459641/normal_602eddf9a5241.pdf
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Embedded domains
- midufefew.ru
- cdn-cms.f-static.net
- static.s123-cdn-static.com
- shop-onlain.fun
- uploads.strikinglycdn.com
- cdn.sqhk.co
- rifimakegezibor.22web.org
- reduslim-buy.site
- slmit.fun
- fimewot.xyz
- limixawur.rf.gd
- pugetuwozijeso.rf.gd
- ludodugadigepez.rf.gd
Embedded IP addresses
- 172.172.255.216
- 85.210.196.11
- 20.42.65.88
- 172.66.2.5
- 52.253.84.76
- 52.110.12.44
- 4.230.171.124
- 40.84.85.40
- 4.150.223.99
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report