MALICIOUS — 974c4014562d7467f362e49105abfac5a433d49b6289d3225b0c32f82ca1fe7a
MALICIOUS — 974c4014562d7467f362e49105abfac5a433d49b6289d3225b0c32f82ca1fe7a is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
974c4014562d7467f362e49105abfac5a433d49b6289d3225b0c32f82ca1fe7a - SHA-1:
ee8a1ef3264ea9956f70dd7b885dd8b8ebf8bb1e - MD5:
917728fec89ceeccc51bc37af53b2aef - ssdeep:
1536:hG/K2fIVf3SbHBVVK+j/tpvtXhLyavE1/F99LyI/TVcB:4/K2Gab9bjmjFFXywTo - TLSH:
T10738CFF36197DCCC7ECB5F93EAE3216A6447C2447232A650048D7B2D88B856E3F519A0 - Submitted as: 974c4014562d7467f362e49105abfac5a433d49b6289d3225b0c32f82ca1fe7a
- File type: pdf · Size: 78544 bytes
- Verdict: malicious (98/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://kuzutuzo.ru/strik?utm_term=essential+university+physics+volume+1+3rd+edition+pdf+download, https://uploads.strikinglycdn.com/files/2a853687-4795-4f62-bc46-de47c7056a67/because_of_winn_dixie_multiple_choice_test.pdf, https://static.s123-cdn-static.com/uploads/4424024/normal_5fcd3d3a43cde.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 5 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (11 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
991 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep(3)._dosvc._tcp.local
- desktop-hsgcbep(4)._dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.85
- 23.11.37.157
- 20.190.167.66
- 20.247.184.197 SG · Singapore · AS8075 Microsoft Corporation
- 150.171.22.17
- 23.33.238.135
- 23.198.40.44
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://kuzutuzo.ru/strik?utm_term=essential+university+physics+volume+1+3rd+edition+pdf+download
- https://uploads.strikinglycdn.com/files/2a853687-4795-4f62-bc46-de47c7056a67/because_of_winn_dixie_multiple_choice_test.pdf
- https://s3.amazonaws.com/rodakarugupoko/samsung_galaxy_3_tablet_manual_download.pdf
- https://static.s123-cdn-static.com/uploads/4424024/normal_5fcd3d3a43cde.pdf
- https://uploads.strikinglycdn.com/files/2f5bf96f-0785-4d26-9bf3-1586e4b2b98c/litok.pdf
- https://bokupotanija.weebly.com/uploads/1/3/5/9/135995636/74ac87ab9f.pdf
- https://uploads.strikinglycdn.com/files/3f39b3cd-2777-4c7a-b4b4-feada8ad8d9e/what_is_metaphysics_according_to_heidegger.pdf
- https://s3.amazonaws.com/lorerexeg/consumer_journey_template.pdf
- https://uploads.strikinglycdn.com/files/6a0546aa-32ed-4fcf-adff-1eae78b75111/fozifixevinol.pdf
- https://cdn-cms.f-static.net/uploads/4401558/normal_6041e4520773c.pdf
- https://s3.amazonaws.com/lakadutof/four_kings_casino_and_slots_trophy_guide.pdf
- https://s3.amazonaws.com/legesiliv/linen_cotton_blend_sheets.pdf
- https://uploads.strikinglycdn.com/files/dd9a5d83-063f-489b-83bf-a1f1afc17ef8/85204709681.pdf
- https://cdn-cms.f-static.net/uploads/4482399/normal_6033db7a8b3db.pdf
- https://s3.amazonaws.com/vavejijitatofu/inner_join_vs_cartesian_product_performance.pdf
- https://uploads.strikinglycdn.com/files/5809efa0-1bcb-4765-8d2a-d7955b3ac151/how_do_i_fix_the_flashing_light_on_my_kitchenaid_blender.pdf
- https://vowabogebem.weebly.com/uploads/1/3/0/7/130775978/sisedagomajo.pdf
- https://s3.amazonaws.com/gizonukorad/shaggy_boombastic_mp4.pdf
- https://s3.amazonaws.com/kobivimelelo/xetetoxovaramexomituwub.pdf
- https://uploads.strikinglycdn.com/files/c14faef3-09ac-4337-a23f-f447565cc89f/saputowom.pdf
- https://uploads.strikinglycdn.com/files/fa6f6e37-efb1-44f7-9d95-59d0d8dbed03/fukuwexefuzezubegeniwom.pdf
- https://s3.amazonaws.com/ruzaganog/52493235345.pdf
- https://static.s123-cdn-static.com/uploads/4489734/normal_5fdffcc54fda0.pdf
- https://s3.amazonaws.com/fajetufekejo/61920724352.pdf
- https://viwoxinuzozaxa.weebly.com/uploads/1/3/1/6/131636825/4563486.pdf
Embedded domains
- kuzutuzo.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- static.s123-cdn-static.com
- bokupotanija.weebly.com
- cdn-cms.f-static.net
- vowabogebem.weebly.com
- viwoxinuzozaxa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 85.210.193.152
- 20.247.184.197
- 4.230.171.124
- 48.211.4.16
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report