MALICIOUS — 8ffaefcba446326a381c37987f62f408a1162071ed93ac3cc870c2f09e94d246
MALICIOUS — 8ffaefcba446326a381c37987f62f408a1162071ed93ac3cc870c2f09e94d246 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8ffaefcba446326a381c37987f62f408a1162071ed93ac3cc870c2f09e94d246 - SHA-1:
d65e0896df0be1b774a91f4cadbbce18bde2a8d0 - MD5:
4bba25d9a1dfc25701310c81be2040f6 - ssdeep:
1536:++dFb6RYM5Pc4ARUCNGy6SBASg03U2D4EWxApOG1tmWkD9P/e:jleYuPuX4BSGv0E2sF3G1tyD9u - TLSH:
T13A37C0F320ABDD4C7A965B076EEB4148A04DE3886172EBD14488B76DD5BC27DBF10910 - Submitted as: 8ffaefcba446326a381c37987f62f408a1162071ed93ac3cc870c2f09e94d246
- File type: pdf · Size: 73060 bytes
- Verdict: malicious (98/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://azizavacanze.com/userfiles/files/figunofixedafan.pdf, http://www.heksan.com.pl/file/fabenixedogugojuzilu.pdf, http://transcash.com/ci/userfiles/files/ligafifixitike.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 7 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1078 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
- 40.126.14.164
- 150.171.22.17
- 23.198.40.44
- 52.110.12.33 US · AS8075 Microsoft Corporation
- 20.190.142.166
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 4.144.132.223 SG · Singapore · AS8075 Microsoft Corporation
- 74.178.240.51 NL · Amsterdam · AS8075 Microsoft Corporation
- 74.179.77.204 US · Moses Lake · AS8075 Microsoft Corporation
- 40.79.141.155 FR · Paris · AS8075 Microsoft Corporation
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/GLLx1DTH0VQ/uplcv?utm_term=android+language+setting
- http://azizavacanze.com/userfiles/files/figunofixedafan.pdf
- http://www.heksan.com.pl/file/fabenixedogugojuzilu.pdf
- http://transcash.com/ci/userfiles/files/ligafifixitike.pdf
- http://mjengo.org/FCKeditor/editor/filemanager/connectors/php/connector.php?Command=FileUpload&Type=File&CurrentFolder=%2Ffile/roxavigorixo.pdf
- http://harrodsrentacar.com/public_html/userfiles/file/56216909134.pdf
- http://studiotecnicobonoli.com/userfiles/files/10540351171.pdf
- https://wscnaturalhealings.com/wp-content/plugins/super-forms/uploads/php/files/dfa6a8321206e1cd017dbf7f9d2600d2/navej.pdf
- http://almawred-sy.com/files/adminfiles/files/19969718568.pdf
- https://f2h63c2.ip4secure.net/upload/files/muwizokajokumovavid.pdf
- http://aksaaydinlatma.com/img/editor/image/file/82545514844.pdf
- https://hamasataccessories.com/userfiles/files/42650007632.pdf
- http://tvkinter.com/file_media/file_image/file/96481295368.pdf
- http://lilipoupoli-drama.gr/lilipoupoli/js/ckfinder/userfiles/files/76290487615.pdf
- http://kurier48.pl/files/userfiles/file/vexunubumuluxaru.pdf
- http://rajasthanmetals.com/userfiles/file/95030523929.pdf
- http://world-housing.jp/ckfinder/userfiles/files/dakumidufabazojisesatesur.pdf
- http://runnersavezzano.it/public/userfiles/file/vokiv.pdf
- https://egca.fr/userfiles/file/83764429909.pdf
- http://savoie-outils-coupants.com/ckfinder/userfiles/files/18452783396.pdf
- http://haki.tincorner.com/uploads/files/64162082984.pdf
- http://hemeringen.de/ckeditor_ablage/userfiles/files/93821991698.pdf
- http://fence-alarm.com/userfiles/files/71580161315.pdf
- http://obkladlazby.cz/userfiles/file/melovuwixonilidoto.pdf
- http://folientastaturen.pl/_data/file/99995254415.pdf
Embedded domains
- feedproxy.google.com
- azizavacanze.com
- www.heksan.com.pl
- transcash.com
- mjengo.org
- harrodsrentacar.com
- studiotecnicobonoli.com
- wscnaturalhealings.com
- almawred-sy.com
- f2h63c2.ip4secure.net
- aksaaydinlatma.com
- hamasataccessories.com
- tvkinter.com
- kurier48.pl
- rajasthanmetals.com
- world-housing.jp
- runnersavezzano.it
- egca.fr
- savoie-outils-coupants.com
- haki.tincorner.com
- hemeringen.de
- fence-alarm.com
- folientastaturen.pl
- ourcampuswindow.com
- kuehllawpc.com
Embedded IP addresses
- 4.150.223.105
- 52.110.12.33
- 4.230.171.124
- 4.144.132.223
- 74.178.240.51
- 74.179.77.204
- 40.79.141.155
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report