MALICIOUS — acaf16f07e0d7cb252e0ad02f85a37ca3c6320db33ff16df973531d8ff619c06
MALICIOUS — acaf16f07e0d7cb252e0ad02f85a37ca3c6320db33ff16df973531d8ff619c06 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100). 3 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
acaf16f07e0d7cb252e0ad02f85a37ca3c6320db33ff16df973531d8ff619c06 - SHA-1:
468f1739ef8e3c0f78fde2819dc8f4f8bd7d2b70 - MD5:
fbeed405b5a0665cb6dc3e905eeb630c - ssdeep:
1536:schP+8hA7h+RpHSuOHsT5Gmbr1TUfR5Ar1rl7y4siwIeWXpO/EW7dQsG8k1ZMF7h:188e7hwJSuOMlGfRiZrlybipe/1QsGIP - TLSH:
T19139D0F3104FAD4CFBCBAA03A5FB1155668FE34D5162E684418C6768C0AC9BDBD20A47 - Submitted as: acaf16f07e0d7cb252e0ad02f85a37ca3c6320db33ff16df973531d8ff619c06
- File type: pdf · Size: 87982 bytes
- Verdict: malicious (97/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://fantasypartyentertainment.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606c7b65a4854---baxovuxori.pdf, https://sakitonus.ru/wp-content/plugins/super-forms/uploads/php/files/dad42fed78798f06c23ccf105a25ecf8/25330801124.pdf, https://kakvkusno26.ru/wp-content/plugins/super-forms/uploads/php/files/c3aa2190ad4970f9e5dbcd15a576774b/91107678909.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 10 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1180 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
- 40.126.14.161
- 52.123.252.239 AU · Sydney · AS8075 Microsoft Corporation
- 23.198.40.44
- 52.110.12.46 AU · Sydney · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.175
- 23.33.238.114
- 52.253.84.76 SG · Singapore · AS8075 Microsoft Corporation
- 20.42.179.204 US · Moses Lake · AS8075 Microsoft Corporation
- 74.179.77.164 US · Moses Lake · AS8075 Microsoft Corporation
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/Om9ozkHLxGw/uplcv?utm_term=how+to+setup+ur5u-8780l-twc
- http://fantasypartyentertainment.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606c7b65a4854---baxovuxori.pdf
- https://sakitonus.ru/wp-content/plugins/super-forms/uploads/php/files/dad42fed78798f06c23ccf105a25ecf8/25330801124.pdf
- https://kakvkusno26.ru/wp-content/plugins/super-forms/uploads/php/files/c3aa2190ad4970f9e5dbcd15a576774b/91107678909.pdf
- https://centar-znr-zop.hr/wp-content/plugins/formcraft/file-upload/server/content/files/1607bb66da9ca4---60109527373.pdf
- http://micronforgacsolo.hu/UserFiles/file/35286571741.pdf
- http://geobrofab.com/clients/d/da/da7cd3953015cd63472398095fc1fcdd/File/nipuvogodewinurat.pdf
- https://janeunchained.com/wp-content/plugins/super-forms/uploads/php/files/dioje3jkspb410nb2c9pd85u40/ziduwipowopozefutojaximo.pdf
- https://pirkitpadangas.lt/ckfinder/userfiles/files/97942418698.pdf
- http://www.allatpatikapecs.hu/images/file/80836187064.pdf
- http://brooklinehs1964.com/clients/6/6a/6a3559cec3eb17f551da2d864c8c85ab/File/veniduwajib.pdf
- http://ackerviewguesthouse.com/userfiles/file/togizapumaderodivagebojir.pdf
- https://sofupingame.com/calisma2/files/uploads/76500772360.pdf
- https://eseninternational.com/uploads/files/28376343205.pdf
- https://pfgmm.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/160beb0ed872a5---zezatunujowe.pdf
- http://antik-cafe-bergen.de/wp-content/plugins/formcraft/file-upload/server/content/files/160a24ef6012e7---suzamusisenibetoxisezu.pdf
- https://relans-nn.ru/images/docs/file/binikutapovijadafaxoga.pdf
- http://studiosantomauro.it/userfiles/files/34229230077.pdf
- https://www.rath-catering.de/wp-content/plugins/formcraft/file-upload/server/content/files/16093aab14bed6---68453088320.pdf
- http://zoop-tech.com/ckfinder/userfiles/files/44779179262.pdf
- https://retentionstudentexperience.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607037cdad393---76420782181.pdf
- https://prtl.pl/userfiles/file/62225718256.pdf
- https://duext.com/wp-content/plugins/super-forms/uploads/php/files/35f3a7d09c731bcfdfb320b83636d16f/vavadojekinakotegerinimuk.pdf
- https://brusroom.com/wp-content/plugins/super-forms/uploads/php/files/63ede3505cb5bee1ff9d0c9d2cbda311/zepabiv.pdf
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- feedproxy.google.com
- fantasypartyentertainment.com
- sakitonus.ru
- kakvkusno26.ru
- geobrofab.com
- janeunchained.com
- brooklinehs1964.com
- ackerviewguesthouse.com
- sofupingame.com
- eseninternational.com
- pfgmm.com.au
- antik-cafe-bergen.de
- relans-nn.ru
- studiosantomauro.it
- www.rath-catering.de
- zoop-tech.com
- retentionstudentexperience.com
- prtl.pl
- duext.com
- brusroom.com
- centar-znr-zop.hr
- micronforgacsolo.hu
- pirkitpadangas.lt
- www.allatpatikapecs.hu
Embedded IP addresses
- 52.123.252.239
- 52.110.12.46
- 4.230.171.124
- 52.253.84.76
- 20.42.179.204
- 74.179.77.164
- 74.178.76.128
- 20.89.1.8
- 72.145.35.106
- 92.223.78.30
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report