MALICIOUS — 779eab062904ad32c2043ed0ce490b41a89137840db032f4582220a023ae6bb9
MALICIOUS — 779eab062904ad32c2043ed0ce490b41a89137840db032f4582220a023ae6bb9 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
779eab062904ad32c2043ed0ce490b41a89137840db032f4582220a023ae6bb9 - SHA-1:
09609dd2b685055a7051aff5e3be200e8eecf38a - MD5:
9f61f928990d32000e0d503761ca15b3 - ssdeep:
3072:0hGPEi/M1LKRYY9LenMN+ijqldlWcI3IuqeE/8f8xggcHOFUpr3:0hGcGAgrVZGldbiryA8v4 - TLSH:
T1283F02E7D163CF4D7A8E9FA30AD6112C704EC2C57622ABD01889326CD9B467E6F54980 - Submitted as: 779eab062904ad32c2043ed0ce490b41a89137840db032f4582220a023ae6bb9
- File type: pdf · Size: 155863 bytes
- Verdict: malicious (99/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 12 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://pelesiuvalymas.lt/i/File/nemubaxolaberobew.pdf, https://hightechrustremovers.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160987b2010d1a---91157774449.pdf, http://www.stratcareerservices.com/wp-content/plugins/formcraft/file-upload/server/content/files/160796b5f0ee14---85266178907.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (17 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
992 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- 23.40.52.85
- 23.11.37.157
- 20.190.142.167
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/zMnd8XtcwSM/uplcv?utm_term=vcredist_arm.+exe+64+bit
- http://pelesiuvalymas.lt/i/File/nemubaxolaberobew.pdf
- https://hightechrustremovers.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160987b2010d1a---91157774449.pdf
- http://www.stratcareerservices.com/wp-content/plugins/formcraft/file-upload/server/content/files/160796b5f0ee14---85266178907.pdf
- https://www.kalirich.com/wp-content/plugins/super-forms/uploads/php/files/kcdqhu6ibmobscea9pb0hmctb0/93473123014.pdf
- http://arci-mp.fr/admin/File/febevasezam.pdf
- http://mas.vacations/wp-content/plugins/formcraft/file-upload/server/content/files/1608a176039b88---88025911615.pdf
- http://mousike.it/img_ins/files/21424705859.pdf
- https://autosofortkauf.ch/wp-content/plugins/super-forms/uploads/php/files/au55hg0oov4lk82nggsblba4q0/31508928632.pdf
- https://mattweidnerlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16084bed218608---63146396933.pdf
- http://supermarketdv.ru/files/file/bazufikujuwegotifojuni.pdf
- http://mouaumfb.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f650a6c3fa---jixojebubuvovu.pdf
- https://islandsvefir.is/wp-content/plugins/super-forms/uploads/php/files/7ad16ao0745ifqf0c80es2kl1s/4337568287.pdf
- https://martybermanassociates.com/wp-content/plugins/super-forms/uploads/php/files/c80e002df12096e1925bb5d405da3247/91373561514.pdf
- https://www.varishastalari.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608c89f15bd5f---goxudi.pdf
- https://kicksomeglass.com/wp-content/plugins/super-forms/uploads/php/files/5807bded68cbcac7595e7cdc4784ee2b/34817832141.pdf
- http://aptchasers.com/FCKeditor/userfiles/file/76088995166.pdf
- https://cananalimdar.com/wp-content/plugins/super-forms/uploads/php/files/86da6hf00je11j7924li30t9vp/31312553583.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- feedproxy.google.com
- hightechrustremovers.nl
- www.stratcareerservices.com
- www.kalirich.com
- arci-mp.fr
- mousike.it
- autosofortkauf.ch
- mattweidnerlaw.com
- supermarketdv.ru
- mouaumfb.com
- martybermanassociates.com
- www.varishastalari.com
- kicksomeglass.com
- aptchasers.com
- cananalimdar.com
- www.w3.org
- purl.org
- ns.adobe.com
- pelesiuvalymas.lt
- mas.vacations
- islandsvefir.is
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 52.230.60.54
- 52.123.252.193
- 52.110.12.2
- 52.110.12.15
- 4.230.171.124
- 135.232.92.97
- 40.84.85.40
- 20.42.73.26
- 85.210.196.11
- 72.145.35.98
- 20.42.72.131
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report