MALICIOUS — 53b073348533190d0361e602dbc66c3ac86366588567228038851fbd726aada4
MALICIOUS — 53b073348533190d0361e602dbc66c3ac86366588567228038851fbd726aada4 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
53b073348533190d0361e602dbc66c3ac86366588567228038851fbd726aada4 - SHA-1:
630c9786831624929247264f936382ab1d7b474a - MD5:
5496abe7a4af47a783fb06ed20517af0 - ssdeep:
1536:U1QhloLwcGnjjxKx9yNjxkPYLt12ZVNaX79t5ugiQZWbpONiWe8GeEvyy:thloLijjIilxaYLOzQL9O3QbNkLhP - TLSH:
T1BD37BFF33197EE4C729BCB4339DA115D540AE3982233D6A1458C7A2CD5BC9BEAF20641 - Submitted as: 53b073348533190d0361e602dbc66c3ac86366588567228038851fbd726aada4
- File type: pdf · Size: 70768 bytes
- Verdict: malicious (99/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://everbeenmagnet.com/js/upfiles/files/75622570922.pdf - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://hantverksakuten.se/ckfinder/userfiles/files/tujixesi.pdf, https://rosedreamholidayhomes.com/ckfinder/userfiles/files/dilotewosuxopevisen.pdf, https://varbackaforskola.se/ckfinder/userfiles/files/durub.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 6 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1004 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.85
- 23.11.37.157
- 40.126.14.164
- 23.33.238.135
- 52.110.12.50 AU · Sydney · AS8075 Microsoft Corporation
- 52.123.252.198 AU · Sydney · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.114
- 23.33.238.102
- 51.132.193.105 GB · London · AS8075 Microsoft Limited UK
- 199.232.138.172
- 2.18.226.150
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/BkSY9tpko7c/uplcv?utm_term=recorder+of+deeds+st+louis+county
- https://hantverksakuten.se/ckfinder/userfiles/files/tujixesi.pdf
- https://rosedreamholidayhomes.com/ckfinder/userfiles/files/dilotewosuxopevisen.pdf
- https://varbackaforskola.se/ckfinder/userfiles/files/durub.pdf
- https://xn--dokumaanahtarlk-llc.net/userfiles/file/refijudilasuvumiduratu.pdf
- http://everbeenmagnet.com/js/upfiles/files/75622570922.pdf
- http://avtokit116.ru/!upload/files/33925556928.pdf
- http://bahtiyardishekimi.com/fckfiles/file/60264759958.pdf
- https://amkboiler.com/wp-content/plugins/super-forms/uploads/php/files/41dsip10mmbljrp83rusjpheis/12169766054.pdf
- http://sola-brothers.com/userfiles/file/99729802329.pdf
- https://biocoop.legreniervert.fr/ckfinder/userfiles/files/35659682253.pdf
- http://merlegdoktor.hu/tmp/16217313307.pdf
- http://dc-07b6a75bc4d0.breakthrough-physical-therapy.com/userfiles/files/6795883438.pdf
- http://decorstore.eu/upload/file/14235389780.pdf
- http://linza-market.ru/upload/files/xuzoko.pdf
- http://www.thaiboat.net/image/upload/File/ronerexebiginepijuzov.pdf
- http://asalsold.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614423edcaf9a---vogosin.pdf
- http://jagdrevier.hu/upload/images/file/18326599878.pdf
- https://piphoto.tw/uploads/files/202109060315314373.pdf
- https://riwg.in/userfiles/file/guxazananakarolag.pdf
- http://medrea.ru/upload/files/wamuki.pdf
- http://sake-tori.com/images/library/File/robixabavetulorisedote.pdf
- https://kujainspectors.com/candyticket/uploads/page_images/files/51001870978.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- hantverksakuten.se
- rosedreamholidayhomes.com
- varbackaforskola.se
- xn--dokumaanahtarlk-llc.net
- everbeenmagnet.com
- avtokit116.ru
- bahtiyardishekimi.com
- amkboiler.com
- sola-brothers.com
- biocoop.legreniervert.fr
- dc-07b6a75bc4d0.breakthrough-physical-therapy.com
- decorstore.eu
- linza-market.ru
- www.thaiboat.net
- asalsold.com
- piphoto.tw
- riwg.in
- medrea.ru
- sake-tori.com
- kujainspectors.com
- www.w3.org
- purl.org
- ns.adobe.com
- merlegdoktor.hu
Embedded IP addresses
- 4.150.223.114
- 52.110.12.50
- 52.123.252.198
- 4.230.171.124
- 51.132.193.105
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report