MALICIOUS — 95304e7a17e9bf6b34509a21238cede0668303a629b6f2a37cdeef8a3f637bcb
MALICIOUS — 95304e7a17e9bf6b34509a21238cede0668303a629b6f2a37cdeef8a3f637bcb is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 3 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
95304e7a17e9bf6b34509a21238cede0668303a629b6f2a37cdeef8a3f637bcb - SHA-1:
4369bfe2f72d19532edbf4ca638f9b37d03dfc24 - MD5:
08da4284d642da932a54ed2fab88f549 - ssdeep:
768:fgmk1CiWF8TWN58dsDwov8+P65vzGXRQxdYh:fgmkERKTdskoI5vzkRQxKh - TLSH:
T10030E0E260CBDD0FF9868F16EBB2827C0C1DE6C5CD58AA52508C4315D0ECD6E3899897 - Submitted as: 95304e7a17e9bf6b34509a21238cede0668303a629b6f2a37cdeef8a3f637bcb
- File type: pdf · Size: 38207 bytes
- Verdict: malicious (98/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 11 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded link rated suspicious by URL analysis: http://gz-chengeng.com/uploadfile/files/wenafoxibo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cplastik.eu/data/cms/file/32455104618.pdf, https://virtrade.gr/userfiles_lybo/file/rixes.pdf, http://gz-chengeng.com/uploadfile/files/wenafoxibo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (8 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1034 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(3)._dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- http://feedproxy.google.com/~r/MbOu/~3/EqozwcbAC44/uplcv?utm_term=what+is+tempera+paint+used+for
- https://cplastik.eu/data/cms/file/32455104618.pdf
- https://virtrade.gr/userfiles_lybo/file/rixes.pdf
- http://gz-chengeng.com/uploadfile/files/wenafoxibo.pdf
- https://qualitycountscleaning.com/wp-content/plugins/super-forms/uploads/php/files/a6016827226519f665c96ced754de39e/puxiwipazunet.pdf
- http://poaglasses.com/uploads/files/202109242355254602.pdf
- http://www.rlktechniek.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1616044b8673a9---wufadunikeliwofuxos.pdf
- http://dangkyidol.com/wp-content/plugins/super-forms/uploads/php/files/bj08a06fovlvungl19m755kr94/babogedejunopazes.pdf
- https://kar360.com/resimler/files/juxesosibunuzupeva.pdf
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- feedproxy.google.com
- cplastik.eu
- gz-chengeng.com
- qualitycountscleaning.com
- poaglasses.com
- www.rlktechniek.nl
- dangkyidol.com
- kar360.com
- virtrade.gr
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 74.178.232.29
- 20.42.65.85
- 20.247.185.124
- 52.123.252.231
- 52.110.12.38
- 4.230.171.124
- 40.84.97.4
- 40.84.85.40
- 72.145.35.104
- 92.223.78.30
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report