MALICIOUS — 679df73e9012c662ddc52f1425bf5f3aacdcb5c59a0af3ba285957f8162e6010
MALICIOUS — 679df73e9012c662ddc52f1425bf5f3aacdcb5c59a0af3ba285957f8162e6010 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
679df73e9012c662ddc52f1425bf5f3aacdcb5c59a0af3ba285957f8162e6010 - SHA-1:
eb004ffe6965fa7be48ce3aa47aaf127e1180c5d - MD5:
591d0f0e3dc8bb4049d941c51ffe9fc2 - ssdeep:
3072:4wt4lgNjO+OKJXFENXplDkrHOWjWUpugxgvcfYoeO8QpRJwzk9UHet5YqnVs:2WjOs1ElYrHhjpuIXQ08QpP9UHetSMG - TLSH:
T1B03FF1F3A4CBDE1EBBD6EB13B6E521453899D24860659F610084BB1D84FC7BE7D00A90 - Submitted as: 679df73e9012c662ddc52f1425bf5f3aacdcb5c59a0af3ba285957f8162e6010
- File type: pdf · Size: 152504 bytes
- Verdict: malicious (98/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://midufefew.ru/strik?utm_term=awol+opm+guidelines, https://0926596c-b1e6-4473-87d6-fed2e709bfeb.filesusr.com/ugd/e2a635_43ae8878cc614ae598b85da0e2fdaf1e.pdf?index=true, https://cdn.sqhk.co/lozuzupadis/z7vibz1/5_pin_bowling_kingston_ontario.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 7 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1074 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- _dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.85
- 23.11.37.157
- 20.190.167.150
- 4.144.132.114 SG · Singapore · AS8075 Microsoft Corporation
- 52.123.252.227 AU · Sydney · AS8075 Microsoft Corporation
- 23.33.238.178
- 52.110.12.18 AU · Sydney · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.171
- 20.184.175.17 US · San Jose · AS8075 Microsoft Corporation
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://midufefew.ru/strik?utm_term=awol+opm+guidelines
- https://0926596c-b1e6-4473-87d6-fed2e709bfeb.filesusr.com/ugd/e2a635_43ae8878cc614ae598b85da0e2fdaf1e.pdf?index=true
- https://cdn.sqhk.co/lozuzupadis/z7vibz1/5_pin_bowling_kingston_ontario.pdf
- https://cdn.sqhk.co/lixipadiwel/jd2hauz/57307515463.pdf
- https://4a5660cc-52a2-48ff-9acb-4b4f1704cb6e.filesusr.com/ugd/81868d_0256b3d642dc44a3ab92e04880169819.pdf?index=true
- https://xefozevinunakab.weebly.com/uploads/1/3/4/3/134340699/pukovix_fagobatipijerin_vekelubo.pdf
- https://guxafosiwu.weebly.com/uploads/1/3/1/4/131453681/7942354.pdf
- https://cdn.sqhk.co/ritapabinap/icvEic0/whatsapp_app_play_store.pdf
- https://cdn-cms.f-static.net/uploads/4413707/normal_602f605497a23.pdf
- https://cdn.sqhk.co/givefugonuw/V9ijWje/59097364617.pdf
- https://1423d76f-a56f-4481-bf87-726e17039346.filesusr.com/ugd/14aee2_fe328cda9fe0467aa300d531819391a1.pdf?index=true
- https://uploads.strikinglycdn.com/files/74c42fbf-9c8b-47a0-886b-5e37d9333b5e/delonghi_dehumidifiers_australia.pdf
- https://kipunelikerave.weebly.com/uploads/1/3/0/9/130969086/nojopapejuvu.pdf
- https://uploads.strikinglycdn.com/files/fa6853a1-58d7-4c3a-b115-ed997541d601/29001488138.pdf
- https://676a7a22-5bec-432e-92e0-9d4a0a27851c.filesusr.com/ugd/a1fb72_05fce09fb6384a86a12081181e36f89a.pdf?index=true
- https://uploads.strikinglycdn.com/files/4304f640-ad81-4666-8f71-98ae8a00c374/mid_america_oireachtas_2020_live_stream.pdf
- https://uploads.strikinglycdn.com/files/b8eec43e-f7d0-4be2-b76c-a219ac22d01c/nugefinewetigojag.pdf
- https://cdn.sqhk.co/wunasesev/XyXJH0Z/hatchimals_colleggtibles_tropical_party_playset_season_4.pdf
- https://povizizumor.weebly.com/uploads/1/3/4/6/134636509/04254766.pdf
- https://5e3b32e6-a537-4a58-a531-ef303a468713.filesusr.com/ugd/120874_dda51e10b59d4f2289c577c6cb8e58fd.pdf?index=true
- https://cdn-cms.f-static.net/uploads/4447649/normal_604e15c39de1c.pdf
- https://14864a69-2465-45da-a912-c6f78a3f99b9.filesusr.com/ugd/409ca8_1fbfd675797b46339ca90117635fbf7d.pdf?index=true
- https://71fc3d66-43b2-4ae0-adc3-dfbcdf8b5360.filesusr.com/ugd/6605a0_0a00dcdfa0794c34820c6019b5f4b918.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- midufefew.ru
- 0926596c-b1e6-4473-87d6-fed2e709bfeb.filesusr.com
- cdn.sqhk.co
- 4a5660cc-52a2-48ff-9acb-4b4f1704cb6e.filesusr.com
- xefozevinunakab.weebly.com
- guxafosiwu.weebly.com
- cdn-cms.f-static.net
- 1423d76f-a56f-4481-bf87-726e17039346.filesusr.com
- uploads.strikinglycdn.com
- kipunelikerave.weebly.com
- 676a7a22-5bec-432e-92e0-9d4a0a27851c.filesusr.com
- povizizumor.weebly.com
- 5e3b32e6-a537-4a58-a531-ef303a468713.filesusr.com
- 14864a69-2465-45da-a912-c6f78a3f99b9.filesusr.com
- 71fc3d66-43b2-4ae0-adc3-dfbcdf8b5360.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 4.144.132.114
- 52.123.252.227
- 52.110.12.18
- 4.230.171.124
- 20.184.175.17
- 72.145.35.98
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report