MALICIOUS — 63c6cf5d789010e138f8ce9f9040ad45ffda66facff487612db158e8ceae4896
MALICIOUS — 63c6cf5d789010e138f8ce9f9040ad45ffda66facff487612db158e8ceae4896 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
63c6cf5d789010e138f8ce9f9040ad45ffda66facff487612db158e8ceae4896 - SHA-1:
dc6c672b76bd12c9a094d265ed54c32e8a619ad7 - MD5:
fc297723358a00a234ba1c4ae1d6ce92 - ssdeep:
1536:WSz3sFIG7hLhWSR+tpIrqtxU2MeyWFajFmidZmxoYW8pO+345B:xz3sm+6SMJzMs4wiTSq+2 - TLSH:
T18D37CFF3618BDC8CB74B9B036DEB112CA489D349A572D65015C4BA6CC47CABEBF20511 - Submitted as: 63c6cf5d789010e138f8ce9f9040ad45ffda66facff487612db158e8ceae4896
- File type: pdf · Size: 74421 bytes
- Verdict: malicious (99/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://ghettaetamionarchitetti.it/userfiles/files/20877409050.pdf - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://medvor.ru/uplcv?utm_term=bertrand+russell+pdf, https://vickers-electronics.co.uk/wp-content/plugins/super-forms/uploads/php/files/08f76f226d375ffcf12281c875af1e98/pupinamot.pdf, https://samuelben-horin.com/userfiles/file/33783116975.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 12 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1008 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 162.159.142.9 US · San Francisco · AS13335 Cloudflare, Inc.
- 23.11.37.157
- 20.190.142.164
- 4.144.132.114 SG · Singapore · AS8075 Microsoft Corporation
- 52.110.12.54 AU · Sydney · AS8075 Microsoft Corporation
- 23.198.40.44
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.207
- 192.168.122.115
- 135.232.92.97 US · Boydton · AS8075 Microsoft Limited
- 199.232.138.172
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://medvor.ru/uplcv?utm_term=bertrand+russell+pdf
- https://vickers-electronics.co.uk/wp-content/plugins/super-forms/uploads/php/files/08f76f226d375ffcf12281c875af1e98/pupinamot.pdf
- https://samuelben-horin.com/userfiles/file/33783116975.pdf
- http://zeamailer.zeapost.com/FCKeditor/editor/filemanager/connectors/userfiles/file/jifipaxir.pdf
- http://foto-preiss.at/upload_files/files/94404621128.pdf
- http://solarwindependence.com/ckfinder/userfiles/files/31614498438.pdf
- https://esterkins.de/ckfinder/userfiles/files/vezojubitu.pdf
- http://www.training4thefuture.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1613b0a315d9bc---kodatipudotigazegagavi.pdf
- https://247christianity.org/fckeditor/userfiles/file/624287553651631960601.pdf
- http://ghettaetamionarchitetti.it/userfiles/files/20877409050.pdf
- http://idroter.org/userfiles/files/pegoj.pdf
- http://hyosangjo.com/userfiles/file/20210907204753.pdf
- https://jjpremiers.com/files/zoxudepuv.pdf
- http://www.kevinbrooks.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1614acd0c0921e---19439946382.pdf
- https://gk-termopanel.ru/wp-content/plugins/super-forms/uploads/php/files/dfb4844b9e39f751660a3616561ff9c5/64751151074.pdf
- https://iphastkala.com/userfiles/file/gixavig.pdf
- http://ahjygjg.com/upload_fck/file/2021-9-21/20210921174649901285.pdf
- http://study4student.com/cache/fck_files/file/dotaw.pdf
- http://www.caribbeandentist.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613e6e0481eda---69907223870.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132e734efe49---14838817369.pdf
- http://altadirezione-consulting.it/userfiles/files/nemulepuzisonenojifunu.pdf
- https://ketdoanbus.com/webroot/img/files/zakigipafavinetuwuralaga.pdf
- https://rumusjitu.com/contents/files/19195979872.pdf
- http://escolacaritas.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614e93f7066a9---sakupopovugenanuzafegos.pdf
- http://kprmk.pl/userfiles/file/tuxisutulixilatas.pdf
Embedded domains
- medvor.ru
- vickers-electronics.co.uk
- samuelben-horin.com
- zeamailer.zeapost.com
- solarwindependence.com
- esterkins.de
- www.training4thefuture.co.uk
- 247christianity.org
- ghettaetamionarchitetti.it
- idroter.org
- hyosangjo.com
- jjpremiers.com
- www.kevinbrooks.ca
- gk-termopanel.ru
- iphastkala.com
- ahjygjg.com
- study4student.com
- www.caribbeandentist.com
- www.1000ena.com
- altadirezione-consulting.it
- ketdoanbus.com
- rumusjitu.com
- escolacaritas.com
- kprmk.pl
- argumentua.com
Embedded IP addresses
- 20.42.179.192
- 40.84.85.40
- 172.172.255.217
- 72.145.35.97
- 162.159.142.9
- 4.144.132.114
- 52.110.12.54
- 4.230.171.124
- 135.232.92.97
- 74.178.240.61
- 172.215.188.232
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report