MALICIOUS — 95e51f0b935f482f90becdb1602999d14765f5d7f2578b1503931a315c746674
MALICIOUS — 95e51f0b935f482f90becdb1602999d14765f5d7f2578b1503931a315c746674 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 3 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
95e51f0b935f482f90becdb1602999d14765f5d7f2578b1503931a315c746674 - SHA-1:
d998a5042515f6fdae4b841a2dde89aa2e6a729e - MD5:
4b11aede6a885d23b6b6f21907986666 - ssdeep:
1536:zdmWWY8n6sAjljmOyCpO7TxDCgBhN4kfuNEqgV/jkEWEApb9ANlaS9W8pO7eTT:BmWWLwoCE71CgBhN/GngpQIApb9A+S8O - TLSH:
T10738D1F321EBDD4C3A9B9F4B69D716E96086E3882172CAD04488B67DD47C27DBE00650 - Submitted as: 95e51f0b935f482f90becdb1602999d14765f5d7f2578b1503931a315c746674
- File type: pdf · Size: 84056 bytes
- Verdict: malicious (94/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 9 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 11 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded link rated suspicious by URL analysis: https://doina.md/fckeditorfiles/file/27400552042.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://bafiti.com/sklep/userfiles/file/95386931547.pdf, http://belean.pl/userfiles/file/niximalelidojud.pdf, https://shining4u.com/wp-content/plugins/super-forms/uploads/php/files/3aa8d0b9987a0629f392d9add66bd323/95189915550.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1009 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ntp.ubuntu.com
- _dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- 23.40.52.209
- 172.66.2.5 US · San Francisco · AS13335 Cloudflare, Inc.
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- http://feedproxy.google.com/~r/Xvkpad/~3/4dZi1sgP-vI/uplcv?utm_term=painting+lessons+pdf
- http://bafiti.com/sklep/userfiles/file/95386931547.pdf
- http://belean.pl/userfiles/file/niximalelidojud.pdf
- https://shining4u.com/wp-content/plugins/super-forms/uploads/php/files/3aa8d0b9987a0629f392d9add66bd323/95189915550.pdf
- https://doina.md/fckeditorfiles/file/27400552042.pdf
- http://dalieuht.com/app/webroot/uploads/files/ramuxesibal.pdf
- http://taiwan-tsai.com/upload/files/31905524909.pdf
- http://erpos.sk/data/files/2938616501.pdf
- http://uniquecharacters.com/upload/files/51390366302.pdf
- http://gruppocaminiti.it/userfiles/files/levifiw.pdf
- http://pk.mo/userfiles/file/soziluxexilatutusifubovot.pdf
- https://lochoanggia.com/upload/files/lijowiladawesisegutelopa.pdf
- https://www.medicalart.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/161642e5e3c681---pevemaf.pdf
- http://associatedreclaimed.com/userfiles/files/duxulurube.pdf
- http://www.sparkprototypes.com/wp-content/plugins/formcraft/file-upload/server/content/files/161606a4b50215---banirasojopajizagova.pdf
- https://zenmobile.in/jaipriyart/uploads/files/pofoj.pdf
- https://www.mftelhas.com.br/adm/Editor/ckfinder/userfiles/files/mesoduvadarubowe.pdf
- https://pediatricpotentialsnj.com/PP/PPpng/files/rowaxamawakekulanafano.pdf
- http://www.guaitoli.eng.br/wp-content/plugins/formcraft/file-upload/server/content/files/161527f32ac712---10260466160.pdf
- http://nj-rshb.com/v15/Upload/file/2021106018313166.pdf
- https://vashadvokat82.ru/wp-content/plugins/super-forms/uploads/php/files/7e1e5c724e0649312e996bf091a1371f/xinowimeropuruxo.pdf
- https://dascalita.ro/app/webroot/files/userfiles/files/piwazisus.pdf
- http://livestocktool.com/d/files/lojagufazonuve.pdf
- https://kaunas.cvzona.lt/resources/img/files/rovopibafelosisasivigam.pdf
- http://cx-gl.hu/images/files/42625070467.pdf
Embedded domains
- feedproxy.google.com
- bafiti.com
- belean.pl
- shining4u.com
- dalieuht.com
- taiwan-tsai.com
- uniquecharacters.com
- gruppocaminiti.it
- lochoanggia.com
- associatedreclaimed.com
- www.sparkprototypes.com
- zenmobile.in
- www.mftelhas.com.br
- pediatricpotentialsnj.com
- www.guaitoli.eng.br
- nj-rshb.com
- vashadvokat82.ru
- livestocktool.com
- tao-oita.com
- www.w3.org
- purl.org
- ns.adobe.com
- doina.md
- erpos.sk
- pk.mo
Embedded IP addresses
- 74.179.71.159
- 4.150.223.97
- 4.207.44.75
- 172.172.255.216
- 72.145.35.97
- 172.215.188.232
- 172.66.2.5
- 52.110.12.32
- 4.230.171.124
- 52.230.60.54
- 72.145.35.106
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report