MALICIOUS — 908666b0fe3d51234783446629a32db3dc1f1c3297f6cc584a9594bd9f674052
MALICIOUS — 908666b0fe3d51234783446629a32db3dc1f1c3297f6cc584a9594bd9f674052 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 3 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
908666b0fe3d51234783446629a32db3dc1f1c3297f6cc584a9594bd9f674052 - SHA-1:
c98b4d494c811b39b365886011f83e0d90a17ef2 - MD5:
714dbda6ef7a8ac2abfab8d7f0b4b6ca - ssdeep:
1536:Vf2G6QpOqCmka+qldfL/Xi9HtvSkeV8PJ4EzvPWM3Lg:4G6Uw5cdfL6RtvBdPuUvjc - TLSH:
T19637E1D300AFDCCCFF4F5B4B4D5A527D918DD3884232E7928089976990AC6BE3E21A51 - Submitted as: 908666b0fe3d51234783446629a32db3dc1f1c3297f6cc584a9594bd9f674052
- File type: pdf · Size: 73781 bytes
- Verdict: malicious (98/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://naosgym.com/userfiles/files/99749346921.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 9 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://incense888.com/uploads/files/202109030512013361.pdf, http://originalbau.hu/imagesfiles/xaredo.pdf, http://naosgym.com/userfiles/files/99749346921.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in Acrobat.exe (pid 3912) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
1036 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- 23.40.52.85
- 23.11.37.157
- 40.126.14.162
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/cv9VXjIrmdE/uplcv?utm_term=picsart+hacked+version+download
- https://incense888.com/uploads/files/202109030512013361.pdf
- http://originalbau.hu/imagesfiles/xaredo.pdf
- http://naosgym.com/userfiles/files/99749346921.pdf
- http://trans-serwis.com/userfiles/file/25921609067.pdf
- https://ambalatender.com/upload/files/60270400713.pdf
- http://socialbomjesus.org.br/wp-content/plugins/formcraft/file-upload/server/content/files/161364bae8a2c5---xopokokadidumamipuzereve.pdf
- http://computergramm.com/userfiles/file/bijozidumujosar.pdf
- http://globomax.eu/userfiles/file/pivitorijutak.pdf
- http://www.polni.si/Images/files/5062434176.pdf
- https://aftaplan.com/works/peepsparty/html/upload_files/file/88647544689.pdf
- http://hoya-system.com/uploads/files/202109121256317900.pdf
- http://galerie45.com/userfiles/file/risutazof.pdf
- http://orthopediedelft.eu/files/zagugafezavejere.pdf
- https://dakhoathienhoa.net/images/files/kepuv.pdf
- https://ateneoarbonaida.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132b0d2b7de7---59988159698.pdf
- https://sca-eagleegg5k.com/ckfinder/triplebuserfiles/file/lavidoladivotovivitewisaj.pdf
- https://tl-systems.hu/files/files/78351979047.pdf
- http://witnesstherealist.com/wp-content/plugins/super-forms/uploads/php/files/45da9b2bc488c7f464462b9ff1d2bc83/motelebonejekefedopujaxin.pdf
- http://abwmechanicsville.com/uploads/files/lebadijuwemeg.pdf
- http://zaun-produzent.de/userfiles/file/14564988255.pdf
- https://zniczekowalczyk.com/user_images/file/9306528889.pdf
- http://skoleniridicu-online.eu/ckfinder/userfiles/files/91519337590.pdf
- http://boonfagrandhome.com/user_img/files/mezosofowi.pdf
- http://myphamlulanjina.com/upload/files/32945743039.pdf
Embedded domains
- feedproxy.google.com
- incense888.com
- naosgym.com
- trans-serwis.com
- ambalatender.com
- socialbomjesus.org.br
- computergramm.com
- globomax.eu
- aftaplan.com
- hoya-system.com
- galerie45.com
- orthopediedelft.eu
- dakhoathienhoa.net
- ateneoarbonaida.com
- sca-eagleegg5k.com
- witnesstherealist.com
- abwmechanicsville.com
- zaun-produzent.de
- zniczekowalczyk.com
- skoleniridicu-online.eu
- boonfagrandhome.com
- myphamlulanjina.com
- eko-gospodarstwo.eu
- originalbau.hu
- www.polni.si
Embedded IP addresses
- 52.110.12.20
- 52.110.12.30
- 40.84.97.4
- 4.230.171.124
- 52.253.84.76
- 74.178.76.54
- 135.232.92.137
- 74.179.77.204
- 57.155.104.224
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report