MALICIOUS — 3b3845cdc2f4adb3966c0268b90163468ab7699ca06fd3e5299db9c58c89c14c
MALICIOUS — 3b3845cdc2f4adb3966c0268b90163468ab7699ca06fd3e5299db9c58c89c14c is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 5 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
3b3845cdc2f4adb3966c0268b90163468ab7699ca06fd3e5299db9c58c89c14c - SHA-1:
3c3050dfd9a5ee3d4e0a050472440e25370630ba - MD5:
6bc6b1c9e9cc0fba71ecba3feae064fa - ssdeep:
1536:UjKBRDX7OqCBvR32xLa2iX+KbqAucDG6phUro4QXyj7T4jtP:/BRDL9ERpnXvqAucBphU04QXyj7Te - TLSH:
T1B638D0F37197CD8CBB895B57B9AA216C1489DB897030EAD54488766CC4B83BE7E00453 - Submitted as: 3b3845cdc2f4adb3966c0268b90163468ab7699ca06fd3e5299db9c58c89c14c
- File type: pdf · Size: 80868 bytes
- Verdict: malicious (99/100)
Detections (5 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!6BC6B1C9E9CC
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PDF/Phish-FAB!6BC6B1C9E9CC (rule
PDF/Phish-FAB!6BC6B1C9E9CC) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded link rated suspicious by URL analysis: https://4407eba0-147d-4e9d-98ff-19010b67f466.filesusr.com/ugd/c1f2fd_30d2ae6de25a42189ce71f7150eb8bf9.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://xajibur.ru/strik?utm_term=how+can+i+send+a+video+from+facebook+to+whatsapp+status, http://bezprovodov.guru/bosewopu6ar38.pdf, https://4407eba0-147d-4e9d-98ff-19010b67f466.filesusr.com/ugd/c1f2fd_30d2ae6de25a42189ce71f7150eb8bf9.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 18 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (11 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1007 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- _dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.85
- 23.11.37.157
- 20.190.167.148
- 52.110.12.8 AU · Sydney · AS8075 Microsoft Corporation
- 52.110.12.55 AU · Sydney · AS8075 Microsoft Corporation
- 23.198.40.44
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.103
- 172.64.154.167 US · San Francisco · AS13335 Cloudflare, Inc.
- 52.253.84.76 SG · Singapore · AS8075 Microsoft Corporation
- 85.210.193.152 GB · AS8075 MICROSOFT-MAINT
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://xajibur.ru/strik?utm_term=how+can+i+send+a+video+from+facebook+to+whatsapp+status
- https://s3.amazonaws.com/pajeriramal/xizufetisusubagofev.pdf
- http://bezprovodov.guru/bosewopu6ar38.pdf
- https://4407eba0-147d-4e9d-98ff-19010b67f466.filesusr.com/ugd/c1f2fd_30d2ae6de25a42189ce71f7150eb8bf9.pdf?index=true
- https://4f65501f-cdae-4966-b9db-49b15ad9d196.filesusr.com/ugd/52b593_d5768f862e6641c6b54754f12ae4149b.pdf?index=true
- https://bivixogerixud.weebly.com/uploads/1/3/4/4/134469213/354773.pdf
- https://xugeguva.weebly.com/uploads/1/3/1/4/131438310/292167.pdf
- http://vasavomuko.iblogger.org/corrupt_file_sample.pdf
- https://s3.amazonaws.com/lukepepe/wafekinakubawa.pdf
- http://puwaxevajineluk.iblogger.org/53231278707.pdf
- http://dayzcommunity.info/guitar_songs_to_learn_fingerstylehst3a.pdf
- https://s3.amazonaws.com/xubifupi/english_daily_words_in_telugu.pdf
- https://zakewurez.weebly.com/uploads/1/3/4/4/134471700/vepas.pdf
- https://s3.amazonaws.com/kavalukato/dixarazunovedinol.pdf
- https://2f8a6ab9-e864-4757-b083-6627a13f4c48.filesusr.com/ugd/405339_6380245f14c34e998b110810ae5469cf.pdf?index=true
- https://cef8af8d-7071-4339-ac50-fc417d371010.filesusr.com/ugd/a89196_499b4b933f34478689395795a10b5d85.pdf?index=true
- https://s3.amazonaws.com/redegelesibif/date_picker_react_native_android.pdf
- http://fetufebutegiv.rf.gd/amazon_web_services_in_action.pdf
- http://jerasopel.epizy.com/11_22_63_clothespin.pdf
- https://kexawugidatenak.weebly.com/uploads/1/3/4/3/134338825/firuwodek-ziwawezonok.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- xajibur.ru
- s3.amazonaws.com
- 4407eba0-147d-4e9d-98ff-19010b67f466.filesusr.com
- 4f65501f-cdae-4966-b9db-49b15ad9d196.filesusr.com
- bivixogerixud.weebly.com
- xugeguva.weebly.com
- vasavomuko.iblogger.org
- puwaxevajineluk.iblogger.org
- dayzcommunity.info
- zakewurez.weebly.com
- 2f8a6ab9-e864-4757-b083-6627a13f4c48.filesusr.com
- cef8af8d-7071-4339-ac50-fc417d371010.filesusr.com
- jerasopel.epizy.com
- kexawugidatenak.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
- bezprovodov.guru
- fetufebutegiv.rf.gd
Embedded IP addresses
- 20.165.94.46
- 57.154.63.210
- 57.155.104.224
- 72.145.35.97
- 20.42.65.90
- 85.210.196.11
- 20.184.175.6
- 85.210.193.152
- 52.110.12.8
- 52.110.12.55
- 4.230.171.124
- 172.64.154.167
- 52.253.84.76
- 4.150.223.104
- 48.211.4.16
- 4.150.223.99
- 72.154.7.98
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report