MALICIOUS — 8b690a7fc133c0ecef19f68b613c658eaed4e59afc3b50a9afc8f5bc3746fbfa
MALICIOUS — 8b690a7fc133c0ecef19f68b613c658eaed4e59afc3b50a9afc8f5bc3746fbfa is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
8b690a7fc133c0ecef19f68b613c658eaed4e59afc3b50a9afc8f5bc3746fbfa - SHA-1:
1b0688f5afc1496e53c09f1870d34e99bc2196f8 - MD5:
54924e87acab106c074400a52970dac7 - ssdeep:
1536:5ectR0n1ZF4gS3s5hgwoTId++nJQUcMW69YJ1ruKPVZW2BziWXpO/IfL:Me+54gSc5Xo0dhJzQVo2BzS/6 - TLSH:
T19837E1F36057DD8CBA9B9F1719F9159E7096C7086172EBA00088766CD4BCBBE7E10901 - Submitted as: 8b690a7fc133c0ecef19f68b613c658eaed4e59afc3b50a9afc8f5bc3746fbfa
- File type: pdf · Size: 74160 bytes
- Verdict: malicious (99/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://yjeverspeed.com/userfiles/file/75546765131.pdf - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://crewmak.ru/uplcv?utm_term=cyberlink+pro+apk, http://maxbrio.kr/files/files/31127009920.pdf, http://agriturismolionsfarm.it/userfiles/files/97184463547.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 10 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1259 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.85
- 23.11.37.157
- 162.159.142.9 US · San Francisco · AS13335 Cloudflare, Inc.
- 20.190.142.163
- 23.33.238.135
- 52.110.12.32 AU · Sydney · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 85.210.196.11 GB · London · AS8075 Microsoft Limited
- 74.178.76.54 IE · Dublin · AS8075 Microsoft Corporation
- 135.232.92.137 US · Boydton · AS8075 Microsoft Limited
- 20.165.94.63 US · San Antonio · AS8075 Microsoft Corporation
- 23.33.238.114
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://crewmak.ru/uplcv?utm_term=cyberlink+pro+apk
- http://maxbrio.kr/files/files/31127009920.pdf
- http://agriturismolionsfarm.it/userfiles/files/97184463547.pdf
- http://pnlestari.com/visitbali/image/files/79034621128.pdf
- http://kcde.kr/userfiles/file/vojesabe.pdf
- http://atmaircenter.com/lb/userfiles/files/79356603048.pdf
- https://parisautotravel.com/wp-content/plugins/super-forms/uploads/php/files/v268mr036hnn873hvq4kg6fvr0/divazag.pdf
- http://annabarons.com/files/files/gamanipupu.pdf
- http://yjeverspeed.com/userfiles/file/75546765131.pdf
- https://pernambucoimortal.com/imagens/files/53499386491.pdf
- https://guptajimarriagebureau.com/userfiles/file/zinexafi.pdf
- https://www.blondel-bois.fr/ckfinder/userfiles/files/tiladeb.pdf
- http://www.appsolutely.sg/wp-content/plugins/formcraft/file-upload/server/content/files/1613ee097b19cd---98514626246.pdf
- http://bipaf.org/2009_home/upload/editor/file/wijokovir.pdf
- http://amexeuro.com/an3_Uploads/file/40433668600.pdf
- https://kurishupally.org/userfiles/file/30772243426.pdf
- https://enilubricant.hoakhanh.vn/uploads/image/files/mopojefub.pdf
- http://titadoorbinhduong.com/upload/files/fizuguguwinobibujafeke.pdf
- https://fortlauderdale-carservice.com/wp-content/plugins/formcraft/file-upload/server/content/files/16131a5ff39125---guxunaw.pdf
- https://twr1115.net/files/fckeditor/file/jogurome.pdf
- http://xn--365-pn7mwb654m2qn.com/ckupload/files/kilafetak.pdf
- http://www.insight-assessment.com/ckfinder/userfiles/files/7250020987.pdf
- http://shmgec.com/Uploadfiles/files/tuvizinini.pdf
- https://aartipalette.com/userfiles/file/85058011354.pdf
- http://biometria.pl/photos_fck/file/tajomezirufubuzonadi.pdf
Embedded domains
- crewmak.ru
- maxbrio.kr
- agriturismolionsfarm.it
- pnlestari.com
- kcde.kr
- atmaircenter.com
- parisautotravel.com
- annabarons.com
- yjeverspeed.com
- pernambucoimortal.com
- guptajimarriagebureau.com
- www.blondel-bois.fr
- www.appsolutely.sg
- bipaf.org
- amexeuro.com
- kurishupally.org
- titadoorbinhduong.com
- fortlauderdale-carservice.com
- twr1115.net
- xn--365-pn7mwb654m2qn.com
- www.insight-assessment.com
- shmgec.com
- aartipalette.com
- biometria.pl
- sinarwaja.com
Embedded IP addresses
- 162.159.142.9
- 52.110.12.32
- 4.230.171.124
- 85.210.196.11
- 74.178.76.54
- 135.232.92.137
- 20.165.94.63
- 40.84.97.4
- 72.153.5.139
- 20.42.65.93
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report