MALICIOUS — 978a9f8315db681486b987a136fc784028007d0a0c6cf613eb2ba692be1d54ed
MALICIOUS — 978a9f8315db681486b987a136fc784028007d0a0c6cf613eb2ba692be1d54ed is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
978a9f8315db681486b987a136fc784028007d0a0c6cf613eb2ba692be1d54ed - SHA-1:
8b0f0ca4406e30694af9afc85f8bf8ea09cb5145 - MD5:
4d1fe2081c25085578733d431ed445f1 - ssdeep:
1536:eCytjJna4dvKh+MYiXKvYqlqu07crfrJaOLJfyVWqNwKdAuoVZWUpO7q6A:/yt1nntK5XoYqlquDrvLJqHrdXoV87o - TLSH:
T18539C0F320ABED8CBF4A9B4765FB11AD648AE38C2166E9500184B67CD4FC0BD2F50561 - Submitted as: 978a9f8315db681486b987a136fc784028007d0a0c6cf613eb2ba692be1d54ed
- File type: pdf · Size: 84641 bytes
- Verdict: malicious (98/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://arabadvertise.com/userfiles/files/169883572.pdf, http://www.jindatunnel.com/up_files/file/gafakenamukupunubiju.pdf, http://homestationrealty.com/userfiles/files/pifox.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 9 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
995 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
- 20.190.142.167
- 23.33.238.135
- 52.110.12.40 AU · Sydney · AS8075 Microsoft Corporation
- 52.110.12.49 AU · Sydney · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.174
- 40.84.97.4 US · Boydton · AS8075 Microsoft Corporation
- 23.40.52.174
- 20.42.179.192 US · Moses Lake · AS8075 Microsoft Corporation
- 23.221.133.185
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/ngfLrbzwjls/uplcv?utm_term=global+wind+system
- https://arabadvertise.com/userfiles/files/169883572.pdf
- http://www.jindatunnel.com/up_files/file/gafakenamukupunubiju.pdf
- http://homestationrealty.com/userfiles/files/pifox.pdf
- http://www.bestlifepolicy.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/161459b0e00853---6711349138.pdf
- http://xedaphcm.com/luutru/files/59985346531.pdf
- http://safaraval.com/basefile/safaravalcom/files/fewurozirugog.pdf
- https://ka-base.no/images_students/files/rofebapanenalakuxisonini.pdf
- https://dubaimotorcycletours.com/uploaded_images/files/66382240085.pdf
- http://rjbmachinery.com/d/files/50866959709.pdf
- http://archinfo.ru/uploads/file/danulamagemijo.pdf
- https://organicfertilizerproduction.com/d/files/kagadewumabudodujiwa.pdf
- https://wlao.on.ca/wp-content/plugins/super-forms/uploads/php/files/e5c88ab4221222881c81e9855ca695af/muwetoxex.pdf
- http://designbyjoseph.com/uploads/File/93070254655.pdf
- https://taybaite.com/userfiles/file/zokefulutelokibo.pdf
- http://2girlstrippin.com/wp-content/plugins/formcraft/file-upload/server/content/files/16150d33123973---rimipajofebuxatufunoze.pdf
- http://st-ark.it/userfiles/files/48922431196.pdf
- http://kelvista.lt/images/files/97404211167.pdf
- https://noks.cz/wp-content/plugins/formcraft/file-upload/server/content/files/1613067e54240e---voluramifezowewaporig.pdf
- https://casasholidays.com/scgtest/team-explore/uploads/files/xakuzabumiritotaxasud.pdf
- http://hoanggiaphatland.com/uploads/image/files/sesarejes.pdf
- http://habitat3.eu/userfiles/files/vobegexegipo.pdf
- https://safewatersolutions.in/ckfinder/userfiles/files/rudebu.pdf
- http://wittlich-luexem.de/userfiles/file/lurege.pdf
- https://ddc-touggourt.dz/ar/files/soziwupafisovosatitif.pdf
Embedded domains
- feedproxy.google.com
- arabadvertise.com
- www.jindatunnel.com
- homestationrealty.com
- www.bestlifepolicy.co.uk
- xedaphcm.com
- safaraval.com
- ka-base.no
- dubaimotorcycletours.com
- rjbmachinery.com
- archinfo.ru
- organicfertilizerproduction.com
- wlao.on.ca
- designbyjoseph.com
- taybaite.com
- 2girlstrippin.com
- st-ark.it
- casasholidays.com
- hoanggiaphatland.com
- habitat3.eu
- safewatersolutions.in
- wittlich-luexem.de
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 135.233.95.80
- 52.178.17.232
- 40.84.85.40
- 92.223.78.30
- 20.42.179.192
- 52.110.12.40
- 52.110.12.49
- 4.230.171.124
- 40.84.97.4
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report