MALICIOUS — 48135701849d002bcd27ade088eca07df0e0dc5ed839bfe53fdb0f428af4c224
MALICIOUS — 48135701849d002bcd27ade088eca07df0e0dc5ed839bfe53fdb0f428af4c224 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
48135701849d002bcd27ade088eca07df0e0dc5ed839bfe53fdb0f428af4c224 - SHA-1:
0df9646e28d8bab425625cb94d92a3efa427bd9b - MD5:
407cdef8865cac8fe80da40ec98afec3 - ssdeep:
1536:TI0z7ReeJQRXK/zg6NF+4W+Aqor/DreTajiQbEWE0qzhj0aILeW8pO7QQt:E0pewQ90LoVqBpQbA0qzhjXILd7r - TLSH:
T11739D1F350E7CD9C7B9F8B8799BF2695708AD2D83221EA5045883A2C947C9BDBF00550 - Submitted as: 48135701849d002bcd27ade088eca07df0e0dc5ed839bfe53fdb0f428af4c224
- File type: pdf · Size: 87050 bytes
- Verdict: malicious (98/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://medvor.ru/uplcv?utm_term=fire+emblem+fates+special+edition+3ds+rom, https://mandalaconfeccao.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/161467d5bef295---wazupula.pdf, https://gemwares.com/userfiles/file/lasovakobowulap.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 6 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1086 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
- 20.190.167.149
- 20.247.184.197 SG · Singapore · AS8075 Microsoft Corporation
- 150.171.22.17
- 52.110.12.19 AU · Sydney · AS8075 Microsoft Corporation
- 52.110.12.49 AU · Sydney · AS8075 Microsoft Corporation
- 4.247.188.233 IN · Pune · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.207
- 192.168.122.106
- 23.33.238.114
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://medvor.ru/uplcv?utm_term=fire+emblem+fates+special+edition+3ds+rom
- https://mandalaconfeccao.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/161467d5bef295---wazupula.pdf
- https://gemwares.com/userfiles/file/lasovakobowulap.pdf
- http://full814.com/upload/files/21625241367.pdf
- https://jss-moms.si/upload/File/85678932300.pdf
- http://bowlingkillers.com/imgdb/files/59880583447.pdf
- http://areopag-group.ru/sites/default/files/uploads/49218254037.pdf
- https://relaxationplusmn.com/wp-content/plugins/super-forms/uploads/php/files/f51023338a8697d58f296bc8bd3e7f5f/49632182725.pdf
- https://www.natursany.com/ckfinder/userfiles/files/12707433577.pdf
- https://xn--22ck6bdp5cach0mc23a.com/ckfinder/userfiles/files/vuxavoze.pdf
- http://mcutech.net/files/paxatusezalawuxexiniser.pdf
- http://stellarp.com/userfiles/files/peruzavuzamadi.pdf
- https://franchisefarm.franchiseharbor.com/files/files/74731189828.pdf
- http://emachn.com/data/attachment/file/76604237546.pdf
- https://hotelmitrutarija.com/uploaded/files/limojuvafidikejigidoni.pdf
- https://anjingliar.com/contents/files/30580071697.pdf
- http://elfuklid.cz/foto/Image/file/10000663874.pdf
- http://goldenmallbiotech.com/upload/files/91504002723.pdf
- https://mcdelandes.ca/uploads/file/jibanija.pdf
- http://posicert.com/upload_fck/file/2021-9-24/20210924152706382220.pdf
- http://www.gieskestukadoors.nl/ckfinder/files/files/1499387782.pdf
- http://www.annaleehuber.com/content_files/file/jepebifozenakeri.pdf
- https://refakatci.net/userfiles/file/xuzularalovazes.pdf
- http://eikenhorstgroep.nl/userfiles/file/86734498488.pdf
- https://sodigital.it/wp-content/plugins/formcraft/file-upload/server/content/files/16146267b9724f---81324220556.pdf
Embedded domains
- medvor.ru
- mandalaconfeccao.com.br
- gemwares.com
- full814.com
- bowlingkillers.com
- areopag-group.ru
- relaxationplusmn.com
- www.natursany.com
- xn--22ck6bdp5cach0mc23a.com
- mcutech.net
- stellarp.com
- franchisefarm.franchiseharbor.com
- emachn.com
- hotelmitrutarija.com
- anjingliar.com
- goldenmallbiotech.com
- mcdelandes.ca
- posicert.com
- www.gieskestukadoors.nl
- www.annaleehuber.com
- refakatci.net
- eikenhorstgroep.nl
- sodigital.it
- benevolo.it
- www.w3.org
Embedded IP addresses
- 20.247.184.197
- 52.110.12.19
- 52.110.12.49
- 4.247.188.233
- 4.230.171.124
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report