MALICIOUS — 8258bba5fc9e4538a9854fced27ee80b4caf3d3a6d83e956765fa3ffbc63aac8
MALICIOUS — 8258bba5fc9e4538a9854fced27ee80b4caf3d3a6d83e956765fa3ffbc63aac8 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 5 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8258bba5fc9e4538a9854fced27ee80b4caf3d3a6d83e956765fa3ffbc63aac8 - SHA-1:
643d67f00afecbdf360c6a09af35d4b22270b7c7 - MD5:
f6bb1d6af597d148e1174ea23e6127ee - ssdeep:
1536:Yx4tIfjvuBqz2pRVvuZcOX6bBPprLHOpaO97iF0wDxswreCgr5tHN3fjAV:2fbz2RUFX6bJdLr66lreCgjVfy - TLSH:
T12A37D0F72697EC4C6F4BAB43A5F91668614ED7482233D5609088B76CD1E83BE7E10E00 - Submitted as: 8258bba5fc9e4538a9854fced27ee80b4caf3d3a6d83e956765fa3ffbc63aac8
- File type: pdf · Size: 73237 bytes
- Verdict: malicious (99/100)
Detections (5 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!F6BB1D6AF597
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PDF/Phish-FAB!F6BB1D6AF597 (rule
PDF/Phish-FAB!F6BB1D6AF597) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://screen.by/images/file/25332063637.pdf, https://ecef-groupe.com/wp-content/plugins/super-forms/uploads/php/files/efl4a3is19s30uh3nr12cmucn4/56041095554.pdf, https://sjalikave.hu/pictures/file/21024369078.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 5 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1023 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep(3)._dosvc._tcp.local
- desktop-hsgcbep(4)._dosvc._tcp.local
- desktop-hsgcbep(5)._dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
- 20.190.167.21
- 52.123.252.197 AU · Sydney · AS8075 Microsoft Corporation
- 23.33.238.135
- 23.198.40.44
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/FevRqgeaUVY/uplcv?utm_term=batman+prey+read+online
- http://screen.by/images/file/25332063637.pdf
- https://ecef-groupe.com/wp-content/plugins/super-forms/uploads/php/files/efl4a3is19s30uh3nr12cmucn4/56041095554.pdf
- https://sjalikave.hu/pictures/file/21024369078.pdf
- http://sns.hu/_user/file/kiwadeguvulariwudop.pdf
- https://greshamgilessalon.com/wp-content/plugins/super-forms/uploads/php/files/f210f75810dc0bc9118e1d126a7ac60d/25602729089.pdf
- http://studiobaliva.eu/userfiles/files/jutimomuvobagogofizadu.pdf
- http://kraljicabih.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606ee5766732a---46603010087.pdf
- http://lotuscourtpune.com/wp-content/plugins/super-forms/uploads/php/files/tvo8jbmgpiq23logshtvcgnld1/nomajinotefakupigutovod.pdf
- http://bellezaeimagen.com.mx/wp-content/plugins/formcraft/file-upload/server/content/files/16077c10967dc9---pazugamejipire.pdf
- https://agrotehholding.ru/wp-content/plugins/super-forms/uploads/php/files/31c562bc44a23411db12f604dc83d51e/16661376989.pdf
- http://www.bridalchapel.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609fd9d9604fb---sozivimel.pdf
- http://ruresept.ru/files/file/45026421518.pdf
- http://www.k-24.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607832b87ca9d---demugapimiso.pdf
- https://webgirls-studio.com/wp-content/plugins/formcraft/file-upload/server/content/files/160caa9eda1f0f---vowavazosojuzizalotu.pdf
- https://universal4shipping.net/userfiles/file/58413218497.pdf
- https://adbadog.com/wp-content/plugins/super-forms/uploads/php/files/149fab8ec075575b319c311008a3ed86/budikerakati.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Embedded domains
- feedproxy.google.com
- ecef-groupe.com
- greshamgilessalon.com
- studiobaliva.eu
- kraljicabih.com
- lotuscourtpune.com
- bellezaeimagen.com.mx
- agrotehholding.ru
- www.bridalchapel.com
- ruresept.ru
- www.k-24.com
- webgirls-studio.com
- universal4shipping.net
- adbadog.com
- www.w3.org
- purl.org
- ns.adobe.com
- screen.by
- sjalikave.hu
- sns.hu
Embedded IP addresses
- 20.42.65.90
- 13.89.179.15
- 52.123.252.197
- 4.230.171.124
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report