MALICIOUS — 6e974700b94e4345dcfa5b093db2d6126985980c04df2e21d6e9c45558e0bf62
MALICIOUS — 6e974700b94e4345dcfa5b093db2d6126985980c04df2e21d6e9c45558e0bf62 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100). 2 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6e974700b94e4345dcfa5b093db2d6126985980c04df2e21d6e9c45558e0bf62 - SHA-1:
4eba4067088337ae4396493d1615ca89720370c7 - MD5:
4b4f02d077f3597c87b246bc02eb30a1 - ssdeep:
1536:CyXw9RXUS3ZYW9eWNAZWHKn46hm2BqqiTJ7L+qN5zETWapOtQ9JGcAbW+Ji3x0Tp:GvXUn+Hwtm2BqqidLp5rtQicApI32p - TLSH:
T1CA38D0F32197DD8C7A8F6A07EAAB519D888ED3485163F6A0548D732DD0BC83EBD04452 - Submitted as: 6e974700b94e4345dcfa5b093db2d6126985980c04df2e21d6e9c45558e0bf62
- File type: pdf · Size: 79404 bytes
- Verdict: malicious (86/100)
Detections (2 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 86/100 is the fusion of 8 weighted signals:
- Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 10 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://huntic.ru/uplcv?utm_term=is+there+an+app+you+can+scan+lottery+tickets, https://phoenixknights.co.uk/wp-content/plugins/super-forms/uploads/php/files/b9463e6d9604a2909911bb37ca7a6b86/xunevirawuwawegonu.pdf, https://pediatricpotentialsnj.com/PP/PPpng/files/28175464869.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in Acrobat.exe (pid 7952) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
1035 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- 23.40.52.209
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://huntic.ru/uplcv?utm_term=is+there+an+app+you+can+scan+lottery+tickets
- https://phoenixknights.co.uk/wp-content/plugins/super-forms/uploads/php/files/b9463e6d9604a2909911bb37ca7a6b86/xunevirawuwawegonu.pdf
- https://pediatricpotentialsnj.com/PP/PPpng/files/28175464869.pdf
- http://gf-location.fr/wp-content/plugins/formcraft/file-upload/server/content/files/16099e9da38586---75818326098.pdf
- http://monkeytailranchdonation.org/clients/e/e8/e82116dd0b5861b0917add2a69208af2/File/62274948746.pdf
- http://cen7dias.es/userfiles/files/laseperajujepopelata.pdf
- http://drukarnia-skawina.pl/app/webroot/media/files/53068782326.pdf
- http://c2mag.com/wp-content/plugins/formcraft/file-upload/server/content/files/160809b218e8aa---46081825800.pdf
- http://aunay-sous-auneau.fr/ckfinder/userfiles/files/wixakoxeguxurenawivefige.pdf
- http://valaptop.com/ImagesVA/file/77440651402.pdf
- https://www.cr-sdc.org/wp-content/plugins/super-forms/uploads/php/files/7f00d1084d487fef591e756eba43871d/61304176523.pdf
- http://matrixuniverzum.eu/wp-content/plugins/formcraft/file-upload/server/content/files/1608085c2f081c---79265138701.pdf
- https://wpsqld.com.au/wp-content/plugins/super-forms/uploads/php/files/a5dd517994be9a319bfe41da6317b5d6/kizagomozirifemiked.pdf
- https://stellabakingcompany.com/wp-content/plugins/formcraft/file-upload/server/content/files/160850c440fe90---mevoretow.pdf
- https://playgametoday.ru/wp-content/plugins/super-forms/uploads/php/files/605bc261400dac208891236e6d942581/73848184925.pdf
- http://www.thebetterinsurance.com/wp-content/plugins/formcraft/file-upload/server/content/files/160be118a39c3d---18923948900.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bb3919f1c93---xesilewosuzawafofatijedep.pdf
- https://gamaconsultores.cl/upload/file/3356443058.pdf
- https://ecoinkworld.com/wp-content/plugins/super-forms/uploads/php/files/4b6e2d110ad58eecfdd316c5cd218934/batezaj.pdf
- http://futurepoolandspa.com/ckfinder/userfiles/files/biroraluzuzuxatojameg.pdf
- https://grootformaatspandoeken.nl/userfiles/file/gavuvobigufodefiwade.pdf
- http://chicagohalo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608f5b1d41d63---jozufulosikosaxoj.pdf
- https://toliveinchristjesus.ceosale.catholic.edu.au/application/third_party/ckfinder/userfiles/files/gazisovezepobokov.pdf
- https://mavismanagement.com/wp-content/plugins/formcraft/file-upload/server/content/files/160fd5e27e09e3---kexumobopufenezimerefe.pdf
- http://pansophers.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609f54d6ef3c5---64694884173.pdf
Embedded domains
- huntic.ru
- phoenixknights.co.uk
- pediatricpotentialsnj.com
- gf-location.fr
- monkeytailranchdonation.org
- cen7dias.es
- drukarnia-skawina.pl
- c2mag.com
- aunay-sous-auneau.fr
- valaptop.com
- www.cr-sdc.org
- matrixuniverzum.eu
- wpsqld.com.au
- stellabakingcompany.com
- playgametoday.ru
- www.thebetterinsurance.com
- www.1000ena.com
- ecoinkworld.com
- futurepoolandspa.com
- grootformaatspandoeken.nl
- chicagohalo.com
- toliveinchristjesus.ceosale.catholic.edu.au
- mavismanagement.com
- pansophers.com
- www.unicodesystems.com
Embedded IP addresses
- 162.159.142.9
- 52.110.12.32
- 52.110.12.47
- 4.230.171.124
- 52.230.60.54
- 135.233.95.144
- 4.150.223.110
- 20.42.65.94
- 57.154.63.210
- 72.154.7.103
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report