MALICIOUS — 8f78d8c04ed5566cd4f07b14cbee3a5d2462c6b2233ac707601e54b80905b68f
MALICIOUS — 8f78d8c04ed5566cd4f07b14cbee3a5d2462c6b2233ac707601e54b80905b68f is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
8f78d8c04ed5566cd4f07b14cbee3a5d2462c6b2233ac707601e54b80905b68f - SHA-1:
28201fe59b09a4b5b6afd6d7ce672108db6bcce1 - MD5:
45e573d2a6c0a39645a72a47e5f8f69c - ssdeep:
1536:SIydxzg4EYA/EysyP4DaJPnojfJQMz+92PWOpOaZBIqU8dqDWRbmmtGKe8fJ:l4zJEpE1Da5nojf892gaZB9UZWbR5f - TLSH:
T14437CFF361BBCC8C779FAF53A9B61619948AD3886221EBD04044B62CD1BCB7D7E11640 - Submitted as: 8f78d8c04ed5566cd4f07b14cbee3a5d2462c6b2233ac707601e54b80905b68f
- File type: pdf · Size: 71097 bytes
- Verdict: malicious (99/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 6 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded link rated suspicious by URL analysis: http://wimborst-ceramics.nl/ckeditor/ckfinder/userfiles/files/dumazoxitabuxegesefuzed.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://chcial.ru/uplcv?utm_term=one+command+creations, http://bibliotekaszamocin.pl/img/upload/files/39773404515.pdf, http://astprom.ru/sites/default/files/file/guguxejonekedejorowo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in Acrobat.exe (pid 2484) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
1131 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- 23.40.52.209
- 23.11.37.157
- 162.159.142.9 US · San Francisco · AS13335 Cloudflare, Inc.
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://chcial.ru/uplcv?utm_term=one+command+creations
- http://bibliotekaszamocin.pl/img/upload/files/39773404515.pdf
- http://astprom.ru/sites/default/files/file/guguxejonekedejorowo.pdf
- https://dmddsgn.com/wp-content/plugins/super-forms/uploads/php/files/76df2a9d7326c7ca5119b23de52fe495/poxaxoraximasoduli.pdf
- http://wimborst-ceramics.nl/ckeditor/ckfinder/userfiles/files/dumazoxitabuxegesefuzed.pdf
- https://nwdglobal.com/ckfinder/userfiles/files/saluvikasinuzavetufelep.pdf
- https://zlato-invest.cz/upload/files/79431120711.pdf
- https://sunpower.lv/ckfinder/userfiles/files/32683339197.pdf
- https://refundsrefunds.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613d0c04dcfc0---kojafitebebiwusemum.pdf
- https://jdsliquorlocker.com/nbloom/fckuploads/file/88012050043.pdf
- http://klaaswester.nl/img/file/podediwoxowubez.pdf
- http://nanoservice.cz/upload/file/30715597533.pdf
- https://soswzgierz.pl/web/uploads/files/71043964571.pdf
- http://liavanhaeringen.nl/userfiles/files/nifesebabifa.pdf
- https://www.tifdip.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613f71a47dd43---32895221158.pdf
- http://maturitni-ples.eu/UserFiles/File/29006756813.pdf
- http://vtvxm.vn/userfiles/file/72835847771.pdf
- https://ptogel2.com/contents/files/18134798749.pdf
- http://fatamorgana.fr/uploads/assets/file/10447750695.pdf
- http://korea-seals.com/ckfinder/userfiles/files/bikaninepoxoxuwuzi.pdf
- http://ebus.cn/up_file/file/74244477440.pdf
- https://vas-vill.hu/userfiles/file/wokoginilofopibawuxilofa.pdf
- https://www.vek-bg.com/app/templates/js/ckfinder/userfiles/files/40784152734.pdf
- http://deeringbayrealestate.com/userfiles/files/buxuz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- chcial.ru
- bibliotekaszamocin.pl
- astprom.ru
- dmddsgn.com
- wimborst-ceramics.nl
- nwdglobal.com
- refundsrefunds.com
- jdsliquorlocker.com
- klaaswester.nl
- soswzgierz.pl
- liavanhaeringen.nl
- www.tifdip.com
- maturitni-ples.eu
- ptogel2.com
- fatamorgana.fr
- korea-seals.com
- ebus.cn
- www.vek-bg.com
- deeringbayrealestate.com
- www.w3.org
- purl.org
- ns.adobe.com
- zlato-invest.cz
- sunpower.lv
- nanoservice.cz
Embedded IP addresses
- 162.159.142.9
- 4.230.171.124
- 4.144.132.223
- 135.232.92.97
- 20.247.185.124
- 85.210.193.152
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report