MALICIOUS — a40c6e05fb0bf919150919c6a672d323e6d37142982575f69e0ca81314200397
MALICIOUS — a40c6e05fb0bf919150919c6a672d323e6d37142982575f69e0ca81314200397 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
a40c6e05fb0bf919150919c6a672d323e6d37142982575f69e0ca81314200397 - SHA-1:
28db51292a155e630b4def13180dcc9589890555 - MD5:
c9729af4ffa68afc7f2bf33879e657f0 - ssdeep:
1536:Jg3sIYc+Kv7B5doc49YV9qfOldYMQUWBzAJHr3I1hnF5ya7/hvgow223tzHWTja4:q1D+KvJozzfOlSMQDBEJLMF5ya7/hv11 - TLSH:
T1603AE0F35197DD8CB2A76B17ADE66329645AD3CC7132A2508088767CC4783EE7E50D40 - Submitted as: a40c6e05fb0bf919150919c6a672d323e6d37142982575f69e0ca81314200397
- File type: pdf · Size: 95714 bytes
- Verdict: malicious (99/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded link rated suspicious by URL analysis: https://91506351-5699-48ce-85e7-8e7d071f4e87.filesusr.com/ugd/d775a9_adc366662af548dc8b603e1ddd1f7dee.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://maypoin.ru/strik?utm_term=blades+in+the+dark+custom+playbooks, https://91506351-5699-48ce-85e7-8e7d071f4e87.filesusr.com/ugd/d775a9_adc366662af548dc8b603e1ddd1f7dee.pdf?index=true, https://zuxogujuwikowe.weebly.com/uploads/1/3/0/9/130969390/591332.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 10 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (11 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1036 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/89c77c08-6078-44b6-8f27-85720154df65/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/89c77c08-6078-44b6-8f27-85720154df65?P1=1788073550&P2=404&P3=2&P4=O%2bb%2fBonlOMyGQTfOOrQ7zKTnEfrCH97ko3rnjaLUaKb%2bxZLwYu4xjvGgi0cI99%2bDJBwbho5g4wrfUlAPgYlfnA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- 23.40.52.209
- 23.11.37.157
- 20.190.142.166
- 23.198.40.44
- 52.110.12.11 AU · Sydney · AS8075 Microsoft Corporation
- 52.110.12.10 AU · Sydney · AS8075 Microsoft Corporation
- 23.221.133.185
- 203.26.79.13 NZ · Auckland · AS24305 EdgeIX Pty Ltd
- 23.33.238.119
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://maypoin.ru/strik?utm_term=blades+in+the+dark+custom+playbooks
- https://91506351-5699-48ce-85e7-8e7d071f4e87.filesusr.com/ugd/d775a9_adc366662af548dc8b603e1ddd1f7dee.pdf?index=true
- https://s3.amazonaws.com/wanalovum/cyber_crime_reporting_in_india.pdf
- https://s3.amazonaws.com/jenisozazewubo/11831016998.pdf
- https://zuxogujuwikowe.weebly.com/uploads/1/3/0/9/130969390/591332.pdf
- https://s3.amazonaws.com/dorobukasawituw/luxawikusodetijetapid.pdf
- https://jomagikovire.weebly.com/uploads/1/3/1/4/131408086/6f96b.pdf
- https://af1bea64-f5cd-41c2-a7c1-97f21c1aa057.filesusr.com/ugd/592671_80eccf65ee0642898fd61c67994558e3.pdf?index=true
- https://02ee9779-94d6-4ec7-959f-c0f99fe19a35.filesusr.com/ugd/cdc607_700e349172124c82b99c4177a339e2f0.pdf?index=true
- https://0ecef3a8-5193-4df1-8dcb-1b7dd0f2be2a.filesusr.com/ugd/e6092c_522b153c1c2544cbb6c5e7f13d9c85fc.pdf?index=true
- https://3b87a2b8-2d13-4e6d-acc4-cbba57692a59.filesusr.com/ugd/50988c_cf18477e99014f1dbbf1c3c25aef1b21.pdf?index=true
- https://3bcdeb60-9876-4d14-bc0a-1dd1632c647c.filesusr.com/ugd/16a96a_5712202431ea43349e011abdfa69a4c3.pdf?index=true
- https://11627308-8c8f-4f08-99ed-0ad85160907d.filesusr.com/ugd/682d1c_16f181170fca4fa6bfbb956f8cc47300.pdf?index=true
- https://s3.amazonaws.com/warapagefasovi/6877579913.pdf
- https://6d706a39-1f93-4f1a-9423-caccf7e65e71.filesusr.com/ugd/69f91f_74908b4385a841d498caa0b2ff5d03bc.pdf?index=true
- https://4fdc5cb1-0646-4ed0-9ac1-f9332ff2c333.filesusr.com/ugd/9b9480_4a793d2b1f6147d5b69261aa24cf72d4.pdf?index=true
- https://s3.amazonaws.com/kuxegu/98463118686.pdf
- https://8acf0fc4-2da8-4686-9788-d7840b5449fc.filesusr.com/ugd/fab691_a37ab67cc62246d8afd607fb4d8af0dc.pdf?index=true
- https://s3.amazonaws.com/mukutud/dining_table_autocad_block.pdf
- https://nonufovoda.weebly.com/uploads/1/3/0/7/130775853/tiletopexoj.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- maypoin.ru
- 91506351-5699-48ce-85e7-8e7d071f4e87.filesusr.com
- s3.amazonaws.com
- zuxogujuwikowe.weebly.com
- jomagikovire.weebly.com
- af1bea64-f5cd-41c2-a7c1-97f21c1aa057.filesusr.com
- 02ee9779-94d6-4ec7-959f-c0f99fe19a35.filesusr.com
- 0ecef3a8-5193-4df1-8dcb-1b7dd0f2be2a.filesusr.com
- 3b87a2b8-2d13-4e6d-acc4-cbba57692a59.filesusr.com
- 3bcdeb60-9876-4d14-bc0a-1dd1632c647c.filesusr.com
- 11627308-8c8f-4f08-99ed-0ad85160907d.filesusr.com
- 6d706a39-1f93-4f1a-9423-caccf7e65e71.filesusr.com
- 4fdc5cb1-0646-4ed0-9ac1-f9332ff2c333.filesusr.com
- 8acf0fc4-2da8-4686-9788-d7840b5449fc.filesusr.com
- nonufovoda.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 4.150.223.113
- 52.110.12.11
- 52.110.12.10
- 203.26.79.13
- 4.230.171.124
- 40.84.97.4
- 52.230.60.54
- 4.207.44.66
- 135.233.95.144
- 20.184.175.18
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report