MALICIOUS — 67df95ee71590762baad65c799b15eb3cf326e928113be0defcad7454b892c2d
MALICIOUS — 67df95ee71590762baad65c799b15eb3cf326e928113be0defcad7454b892c2d is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
67df95ee71590762baad65c799b15eb3cf326e928113be0defcad7454b892c2d - SHA-1:
548cfb85ff9e6fd8d370e235c959c1e6ef62d956 - MD5:
71de6a25dcbd619419ae21c250aea3dd - ssdeep:
1536:f+myytHE85QGn3IvcRVBhMkngiVQ6X3+GmWYaBIvXDZZWbpONnVRs6WFM:/bHEsn3xhtnlGM3iaoXDZbNnkRS - TLSH:
T1DC37C0F320E7DE4C3A8BAF4369EA1164904AD7486261DB90508C77BDC1BC5BEAF54A10 - Submitted as: 67df95ee71590762baad65c799b15eb3cf326e928113be0defcad7454b892c2d
- File type: pdf · Size: 75814 bytes
- Verdict: malicious (99/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 17 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://laborke.ru/uplcv?utm_term=prop+hunt+fortnite+toy+story+code, https://mehreganimaging.com/images/upload/files/vodukigibiside.pdf, http://holmeslawfirm-iowa.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/vexob.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1005 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- 23.40.52.85
- 23.11.37.157
- 40.126.14.161
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://laborke.ru/uplcv?utm_term=prop+hunt+fortnite+toy+story+code
- https://mehreganimaging.com/images/upload/files/vodukigibiside.pdf
- http://holmeslawfirm-iowa.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/vexob.pdf
- https://tectrongim.com/uploads/file/ponesawe.pdf
- https://vipbeachhouse.com/uploads/editor/file/57324210257.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614ae3afd7695---wesajatomesofekaserobike.pdf
- https://universal4shipping.net/userfiles/file/53959962342.pdf
- http://daehwa.info/uploaded/file/13042955563.pdf
- https://goez1.com/10005001208290177/ckfinder/userfiles/files/nufoxefa.pdf
- http://rs-entp.com/upload/file/37286178631.pdf
- https://rhdplumbing.com/wp-content/plugins/super-forms/uploads/php/files/3535e44dd34e9538d89e1f9e72f0b00a/sunam.pdf
- http://hnfhdc.com/UpLoadFile/2021100512011680862.pdf
- http://ammk.sk/userfiles/file/36604592066.pdf
- https://vresponse.net/userfiles/file/jotafomo.pdf
- http://majorpropertygroup.com/userfiles/files/zulome.pdf
- http://affectif.ro/data/Image/file/ragejeveti.pdf
- http://suachuamaydemtien.biz/userfiles/file/pukodajofulowujukil.pdf
- https://flylights.pl/wp-content/plugins/super-forms/uploads/php/files/nhi9kbug8i1ib4ujru8tvv2uet/28760860215.pdf
- http://deeringbayrealestate.com/userfiles/files/jigomazopoturusubaso.pdf
- https://ytdrive.com/CKEdit/upload/files/natiroromagidinurupujoxo.pdf
- https://bjjewels.net/nbloom/fckuploads/file/dijunelasisiku.pdf
- http://conniecorsentino.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/naxakebozazoxowefar.pdf
- http://csim.jp/ckeditor/uploads/files/79576009714.pdf
- https://educationindiajournal.org/ckfinder/userfiles/files/mapemuka.pdf
- http://malbreil.com/userfiles/file/96612282727.pdf
Embedded domains
- laborke.ru
- mehreganimaging.com
- holmeslawfirm-iowa.com
- tectrongim.com
- vipbeachhouse.com
- www.1000ena.com
- universal4shipping.net
- daehwa.info
- goez1.com
- rs-entp.com
- rhdplumbing.com
- hnfhdc.com
- vresponse.net
- majorpropertygroup.com
- suachuamaydemtien.biz
- flylights.pl
- deeringbayrealestate.com
- ytdrive.com
- bjjewels.net
- conniecorsentino.com
- csim.jp
- educationindiajournal.org
- malbreil.com
- www.artikel238.nl
- mimpidia.com
Embedded IP addresses
- 85.210.193.152
- 40.84.97.4
- 20.42.72.131
- 57.155.101.212
- 20.89.1.10
- 85.210.196.11
- 20.89.1.13
- 52.123.252.198
- 52.110.12.47
- 4.230.171.124
- 172.215.188.232
- 172.64.154.167
- 52.230.59.222
- 135.232.92.97
- 74.178.76.128
- 51.11.192.51
- 72.145.35.101
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report