MALICIOUS — 8acfb68851b54af42972323808f7bfc9f1f9929644d49dbfc1978d8925b0f3b4
MALICIOUS — 8acfb68851b54af42972323808f7bfc9f1f9929644d49dbfc1978d8925b0f3b4 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8acfb68851b54af42972323808f7bfc9f1f9929644d49dbfc1978d8925b0f3b4 - SHA-1:
2d73d37d9635b2d016226f1c41d2fd965cd03523 - MD5:
e62134fd675b90e1d7f53ed9a9551206 - ssdeep:
1536:Ewj36NQblc86PP51HRTWuqQ55BFWZFGOrGjv40y1WwqCnbxWUpO78cW:VqWN6PP51H0fQbK4Oov4X4Cnb07c - TLSH:
T13838C0F3208BED8C774B9B077A9B116CB84AD3946132EA604088FB6CC5BC57DBE14651 - Submitted as: 8acfb68851b54af42972323808f7bfc9f1f9929644d49dbfc1978d8925b0f3b4
- File type: pdf · Size: 78550 bytes
- Verdict: malicious (99/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 11 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://irlanc.ru/uplcv?utm_term=hey+there+dej+loaf+mp3+download, http://gradn.ru/uploades/fckeditorfile/kejupejok.pdf, https://bodzlomu.com/userfiles/file/84871798111.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in Acrobat.exe (pid 3164) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
1032 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ntp.ubuntu.com
- _dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- 23.40.52.85
- 23.11.37.157
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://irlanc.ru/uplcv?utm_term=hey+there+dej+loaf+mp3+download
- http://gradn.ru/uploades/fckeditorfile/kejupejok.pdf
- https://bodzlomu.com/userfiles/file/84871798111.pdf
- http://ip-golubev.ru/ckfinder/userfiles/files/56762259549.pdf
- https://mikepromedia.com/wp-content/plugins/super-forms/uploads/php/files/12fd733940437d5262fdbd584d0173d8/98018783507.pdf
- http://mimarathi.live/assets/ckfinder/core/connector/php/uploads/files/punalumamebepitop.pdf
- https://kolodezrus.ru/wp-content/plugins/super-forms/uploads/php/files/d4a54e244d0ec603ac21323d06764e95/sagoxukivujepiwafewop.pdf
- https://activsport.ro/userfiles/file/48408051502.pdf
- http://mail.teleserviciomalaga.com/ckfinder/userfiles/files/68380630179.pdf
- https://terminarz.online/kosmetyczka/krakow/files/939480783.pdf
- https://tipresentoio.it/images/file/gizefapitizovokafizom.pdf
- http://7m-shop.com/userfiles/file/nisebotabuv.pdf
- http://thefutureofgolf.eu/wp-content/plugins/formcraft/file-upload/server/content/files/16156fd59a4fbd---32228807503.pdf
- http://hamzalegalservices.com/userfiles/file/supipelewolamudoxaxotilup.pdf
- http://guides2alpes.org/uploads/file/65724753947.pdf
- http://fotografieindex.nl/images/uploads/rulipuzugemutab.pdf
- https://buildingexpertsdirectory.com/ckfinder/userfiles/files/jonedunabikukejumuvaw.pdf
- http://dichvumucin.com/upload/ckupload/files/46553201014.pdf
- http://alternativefitness.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16130fcd1e85a9---zijinavijitowuwaxu.pdf
- http://csc0311.com/userfiles/file/20210906195624_72ux93.pdf
- https://thefencedocumentary.com/adminfiles/file/porimom.pdf
- http://kowel.com/ckfinder/userfiles/files/1631963573.pdf
- http://werder-ritter.de/UserFiles/File/bugutejebabezubegekisi.pdf
- https://atlastoursntravels.com/userfiles/file/jomutafelibej.pdf
- https://www.kadeavenue.com/wp-content/plugins/super-forms/uploads/php/files/e267bd7505a1169d54acae029b7cf2d3/90726596088.pdf
Embedded domains
- irlanc.ru
- gradn.ru
- bodzlomu.com
- ip-golubev.ru
- mikepromedia.com
- mimarathi.live
- kolodezrus.ru
- mail.teleserviciomalaga.com
- terminarz.online
- tipresentoio.it
- 7m-shop.com
- thefutureofgolf.eu
- hamzalegalservices.com
- guides2alpes.org
- fotografieindex.nl
- buildingexpertsdirectory.com
- dichvumucin.com
- alternativefitness.com.au
- csc0311.com
- thefencedocumentary.com
- kowel.com
- werder-ritter.de
- atlastoursntravels.com
- www.kadeavenue.com
- www.w3.org
Embedded IP addresses
- 40.84.85.40
- 85.210.193.152
- 203.26.79.13
- 172.172.255.218
- 52.123.252.248
- 52.110.12.14
- 52.110.12.50
- 4.230.171.124
- 51.132.193.105
- 4.247.188.233
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report