MALICIOUS — a15121f63e6c5e74857f945257d897844adae6d3af11bb16db58c775ad538672
MALICIOUS — a15121f63e6c5e74857f945257d897844adae6d3af11bb16db58c775ad538672 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 5 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a15121f63e6c5e74857f945257d897844adae6d3af11bb16db58c775ad538672 - SHA-1:
241c6f37f0cb1ff597fc9dc7fa624812c31bacd4 - MD5:
0b6aac57da78d5aaeb0474cd08762846 - ssdeep:
1536:9FdJdVI13Oo3RhtLLllEdVXlxaGIhzWclpVTUQF6T4mXZoKyl:FJdU35RhtdCl4GEb5ET4mXZoL - TLSH:
T13438C0F760C7CC5CB98BAB639E561668598FD2C92032D7A040D8B61D987C5FE7E50B00 - Submitted as: a15121f63e6c5e74857f945257d897844adae6d3af11bb16db58c775ad538672
- File type: pdf · Size: 77797 bytes
- Verdict: malicious (99/100)
Detections (5 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!0B6AAC57DA78
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PDF/Phish-FAB!0B6AAC57DA78 (rule
PDF/Phish-FAB!0B6AAC57DA78) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 7 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://huntic.ru/pbw?utm_term=rocky+kannada+movie+mp3+songs+free+download, https://uploads.strikinglycdn.com/files/44d640f9-6d8b-43d9-9490-b549a50f39f9/the_hunger_games_mockingjay_part_2_full_movie_download_in_tamil.pdf, https://cdn-cms.f-static.net/uploads/4425256/normal_5fdb577f6e246.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1076 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- _dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- 192.168.122.115
- 23.40.52.85
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://huntic.ru/pbw?utm_term=rocky+kannada+movie+mp3+songs+free+download
- https://uploads.strikinglycdn.com/files/44d640f9-6d8b-43d9-9490-b549a50f39f9/the_hunger_games_mockingjay_part_2_full_movie_download_in_tamil.pdf
- https://cdn-cms.f-static.net/uploads/4425256/normal_5fdb577f6e246.pdf
- https://uploads.strikinglycdn.com/files/b036a8c2-0ee3-4f3f-abc0-3b896b0617a9/property_management_job_titles_list.pdf
- https://uploads.strikinglycdn.com/files/68440f2c-6e94-4d34-83c4-54acf4ba7652/resumo_do_livro_de_paulo_freire_pedagogia_do_oprimido.pdf
- https://cdn-cms.f-static.net/uploads/4488349/normal_60675d1855493.pdf
- https://uploads.strikinglycdn.com/files/25baf527-a88c-4317-9cc2-9e6049fa3e63/kisidowakeke.pdf
- https://cdn-cms.f-static.net/uploads/4465539/normal_606e3001c9c63.pdf
- https://cdn-cms.f-static.net/uploads/4410441/normal_6062da309edcb.pdf
- https://uploads.strikinglycdn.com/files/e36a5827-1b61-4aa6-b726-b017e48c2395/90662163432.pdf
- https://netodidomaxamoz.weebly.com/uploads/1/3/4/3/134311991/47bae4f48173.pdf
- https://static.s123-cdn-static.com/uploads/4454575/normal_6001d5aeaa6e2.pdf
- https://uploads.strikinglycdn.com/files/621307ba-e002-41e2-8d9f-1394dad326a1/3_day_potty_training_book_amazon.pdf
- https://static.s123-cdn-static.com/uploads/4448976/normal_5fed3dd81b82c.pdf
- https://uploads.strikinglycdn.com/files/bd768f3f-0f06-401f-9530-631084ea15cb/87069211549.pdf
- https://uploads.strikinglycdn.com/files/237e85cb-9e84-4ead-bbfb-022082912d62/43233150214.pdf
- https://uploads.strikinglycdn.com/files/d4ae4648-4a92-4cc4-9981-044e01764f41/apple_ipod_shuffle_2gb_user_manual.pdf
- https://nufujemirifo.weebly.com/uploads/1/3/4/8/134868255/3728055.pdf
- https://static.s123-cdn-static-d.com/uploads/4501777/normal_60b0060896a73.pdf
- https://uploads.strikinglycdn.com/files/e79bc3c3-00e2-4797-8e15-c58cafbe0c3b/36814357460.pdf
- https://uploads.strikinglycdn.com/files/62d2d2a6-24af-42fc-b153-19aec1449eda/comcast_remote_code_for_element_led_tv.pdf
- https://cdn-cms.f-static.net/uploads/4415327/normal_5fd14c0d1c1a4.pdf
- https://uploads.strikinglycdn.com/files/288e8a78-8395-4cd1-ba47-381e0dbc2114/89256013248.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- huntic.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- netodidomaxamoz.weebly.com
- static.s123-cdn-static.com
- nufujemirifo.weebly.com
- static.s123-cdn-static-d.com
- www.w3.org
- purl.org
- ns.adobe.com
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 52.123.252.242
- 52.110.12.20
- 52.110.12.54
- 4.230.171.124
- 4.247.188.224
- 20.42.73.25
- 57.154.63.210
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report