MALICIOUS — b8d9626d08b126754cedd0bde6b6a0e08090873b14c82862c8b9b68b57e70370
MALICIOUS — b8d9626d08b126754cedd0bde6b6a0e08090873b14c82862c8b9b68b57e70370 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b8d9626d08b126754cedd0bde6b6a0e08090873b14c82862c8b9b68b57e70370 - SHA-1:
6e5ce8b2fdce367e4bdb848b9de854067fe29c31 - MD5:
7dd12500c2ba24cb3680994773fa79f6 - ssdeep:
1536:imG8MdnmtyAYAFtLtXwXu8j0VKBrK5dunD6cQTvacNOPYHAW0afFTWspO2xPB:qhdnmbYAHLlW0QBWqneLTScNOPYH/O2D - TLSH:
T10939CFF320A7DD4C77568F536EBA21ADA089E78D3122EA9051C87A7CC47C57DAF20610 - Submitted as: b8d9626d08b126754cedd0bde6b6a0e08090873b14c82862c8b9b68b57e70370
- File type: pdf · Size: 84386 bytes
- Verdict: malicious (98/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://emotionalgift.youngzonejewelry.com/ckfinder/userfiles/files/neximikizili.pdf, https://equimat-cheval.fr/file/kepemum.pdf, http://www.physedu.in/newsite/userfiles/files/rubapidukekazavuwudezamux.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 10 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1008 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep(3)._dosvc._tcp.local
- desktop-hsgcbep(4)._dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.85
- 23.11.37.157
- 20.190.167.66
- 20.247.184.142 SG · Singapore · AS8075 Microsoft Corporation
- 150.171.22.17
- 52.110.12.30 AU · Sydney · AS8075 Microsoft Corporation
- 23.198.40.44
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/1KS0DP0cxss/uplcv?utm_term=how+to+unhighlight+in+pdf
- https://emotionalgift.youngzonejewelry.com/ckfinder/userfiles/files/neximikizili.pdf
- https://equimat-cheval.fr/file/kepemum.pdf
- http://www.physedu.in/newsite/userfiles/files/rubapidukekazavuwudezamux.pdf
- http://sjar-tech.com/uploadfile/file///2021100509281094.pdf
- http://bjaimama.com/data/upload/2021/09/file/202109250028289543.pdf
- https://easyown.ddproperty.com/datas/files/gajarikolevaxo.pdf
- https://terracell.info/images/file/zefimiximumegebovotizu.pdf
- http://bnblspecialities.com/userfiles/files/81761522851.pdf
- https://alcc.vn/wp-content/plugins/super-forms/uploads/php/files/o1ludne6vtp67bb8esf7uvi74s/96786094101.pdf
- http://seattledesis.com/fckeditor/file/xabotesamagudosuvuxizaxuk.pdf
- http://atletika-pardubice.cz/files/file/gisudunawegubadi.pdf
- http://pop-around.com/file_media/file_image/file/88905247183.pdf
- http://omni-links.com/images/blog/file/nowizelumosujutegesufew.pdf
- http://www.guus.edu.mn/ckfinder/userfiles/files/giwumobexekaki.pdf
- https://tavfelugyelet.megujuloenergiapark.hu/admin/ckfinder/userfiles/files/dovovixazapowaruwo.pdf
- https://mayxaydungthienlong.com/uploads/files/files/simexisekerorazozosofew.pdf
- https://www.colegiodesafio.net/home/wp-content/plugins/formcraft/file-upload/server/content/files/16152653f0a99c---51321393299.pdf
- https://edgecs.com/documents/96655917516.pdf
- http://mackits.eu/image/77898834658.pdf
- http://dienlanhlongan.com/upload/files/89091690380.pdf
- https://best-of-geldanlagen.de/userfiles/file/mozutudovavi.pdf
- http://daming-school.com/userfiles/file/11551550602.pdf
- https://socialacademy.gr/wp-content/plugins/super-forms/uploads/php/files/44c63ced32505069457165ef1f3b7d5a/65211174273.pdf
- https://kanalprofi.at/UserFiles/file/35306996427.pdf
Embedded domains
- feedproxy.google.com
- emotionalgift.youngzonejewelry.com
- equimat-cheval.fr
- www.physedu.in
- sjar-tech.com
- bjaimama.com
- easyown.ddproperty.com
- terracell.info
- bnblspecialities.com
- seattledesis.com
- pop-around.com
- omni-links.com
- mayxaydungthienlong.com
- www.colegiodesafio.net
- edgecs.com
- mackits.eu
- dienlanhlongan.com
- best-of-geldanlagen.de
- daming-school.com
- www.w3.org
- purl.org
- ns.adobe.com
- alcc.vn
- atletika-pardubice.cz
- www.guus.edu.mn
Embedded IP addresses
- 72.145.35.96
- 72.153.5.130
- 20.247.184.142
- 52.110.12.30
- 4.230.171.124
- 4.150.223.97
- 74.179.77.204
- 51.11.192.50
- 85.210.193.152
- 92.223.78.30
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report