MALICIOUS — 8320113e1cabce133f2b10b8b22d0fdbbd01cdd0149c2466f20c56a5218023d0
MALICIOUS — 8320113e1cabce133f2b10b8b22d0fdbbd01cdd0149c2466f20c56a5218023d0 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8320113e1cabce133f2b10b8b22d0fdbbd01cdd0149c2466f20c56a5218023d0 - SHA-1:
9062f0b1df213f80cc5ed43cd42d506fd0ad4eec - MD5:
26a2ea68e809e394fa4f56671d49355d - ssdeep:
1536:wbV24gunocqeL/tQNJPnErLZ3Pb7R+CWS5a33Cne9yapIW8pO+gWTr/xhOVMlGip:4VVLnomLkJPOZPPwCF5a3Ses0z+7r/xR - TLSH:
T14839C0F331D7DD8C775FCB136CA622696086D79825A2DA9084CC767C85BC6BEBE00910 - Submitted as: 8320113e1cabce133f2b10b8b22d0fdbbd01cdd0149c2466f20c56a5218023d0
- File type: pdf · Size: 86178 bytes
- Verdict: malicious (99/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 15 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://fasson.vip/images/editor/files/tojagamiz.pdf, http://xmzhj.com/UserFiles/file/rososebovenarexidobufamox.pdf, https://desense.eu/uploads/wysiwyg/files/1928098741.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1014 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- 23.40.52.209
- 23.11.37.157
- 172.66.2.5 US · San Francisco · AS13335 Cloudflare, Inc.
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/LPIa9PGmDLg/uplcv?utm_term=put+cinema+hd+on+firestick
- http://fasson.vip/images/editor/files/tojagamiz.pdf
- http://xmzhj.com/UserFiles/file/rososebovenarexidobufamox.pdf
- https://desense.eu/uploads/wysiwyg/files/1928098741.pdf
- https://sieuviet.net/webroot/img/files/50791250001.pdf
- https://apoc.com.au/wp-content/plugins/super-forms/uploads/php/files/b14008d4c4dc10f417c2fee706aa2ff8/tigepibupuni.pdf
- https://copacndg.com/images/uploads/files/jilofufunipawakokonal.pdf
- http://dobre-jaja.com/Upload/file/39566884600.pdf
- http://rockhousemethod.com/ckfinder/userfiles/files/zarewudiworowojeli.pdf
- http://nenayu.com/filespath/files/20210912030234.pdf
- http://gnatowski.pl/attachments/file/25330129417.pdf
- https://durgabas.coop.np/ckfinder/userfiles/files/panuxopaxetaloliwulano.pdf
- http://beveragesgs.com/userfiles/file/wozasaz.pdf
- https://praktijk-fix.nl/userfiles/image/file/vosozaxuzamufijize.pdf
- http://americasbestwingspa.iorderfoods.com/uploads/files/nawuxatisuvomogaxewi.pdf
- http://manpukulivermore.com/uploads/files/rewegupiliwo.pdf
- https://tttinox.com/upload/userfiles/files/pilinerodewoxizawusunawu.pdf
- https://masterpieces-mallorca.com/wp-content/plugins/super-forms/uploads/php/files/f2f8110766dba0a024c0c9e169bc9222/86620203601.pdf
- http://ippinnudon.com/uploads/files/54897757265.pdf
- https://deesudcoolingtower.com/userfiles/file/99810148723.pdf
- http://nhatrangpalace.net/app/webroot/upload/files/25356122181.pdf
- http://dichvutheapec.com/upload/FCK/file/zenekugoxivano.pdf
- http://0vote.com/ckfinder/files/tifaximewilizasa.pdf
- http://mavelikaradiocese.org/rapha/ckfinder/userfiles/files/tegid.pdf
- https://francoisdaulte.com/ckfinder/userfiles/files/gudemikipinigedaten.pdf
Embedded domains
- feedproxy.google.com
- fasson.vip
- xmzhj.com
- desense.eu
- sieuviet.net
- apoc.com.au
- copacndg.com
- dobre-jaja.com
- rockhousemethod.com
- nenayu.com
- gnatowski.pl
- beveragesgs.com
- praktijk-fix.nl
- americasbestwingspa.iorderfoods.com
- manpukulivermore.com
- tttinox.com
- masterpieces-mallorca.com
- ippinnudon.com
- deesudcoolingtower.com
- nhatrangpalace.net
- dichvutheapec.com
- 0vote.com
- mavelikaradiocese.org
- francoisdaulte.com
- crabandclaw.com
Embedded IP addresses
- 40.84.85.40
- 85.210.196.11
- 57.155.101.212
- 51.116.246.104
- 57.154.63.210
- 172.66.2.5
- 52.110.12.32
- 4.230.171.124
- 172.215.188.225
- 135.232.92.97
- 52.168.117.168
- 135.232.92.137
- 20.165.94.63
- 20.42.65.94
- 20.184.175.5
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report