MALICIOUS — bb0fcddcf91816f0efa5a5d0c142aa07d68d3f29bb6decbd15245e20c87a7d39
MALICIOUS — bb0fcddcf91816f0efa5a5d0c142aa07d68d3f29bb6decbd15245e20c87a7d39 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 5 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bb0fcddcf91816f0efa5a5d0c142aa07d68d3f29bb6decbd15245e20c87a7d39 - SHA-1:
23665d72cf50f6fa692998c1fb1029e6c3ba004c - MD5:
53c016d7d56f61397d198407aa24f928 - ssdeep:
1536:p94/QsmPSHCD89RvLziOzGGlkITxxCyS5FX+uE1LRW66UealPiABmKrY:WQIg895LzBzPlk2RYX72VWjUeVAkKs - TLSH:
T13438CFF36193DE8C7A47AB4399B7155D608B939C75339B945888BA6CC03C3BE7E20910 - Submitted as: bb0fcddcf91816f0efa5a5d0c142aa07d68d3f29bb6decbd15245e20c87a7d39
- File type: pdf · Size: 81024 bytes
- Verdict: malicious (99/100)
Detections (5 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!53C016D7D56F
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PDF/Phish-FAB!53C016D7D56F (rule
PDF/Phish-FAB!53C016D7D56F) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://baarspo.ru/strik?utm_term=armitron+wr165ft+set+time, https://uploads.strikinglycdn.com/files/3fd8c70c-71c4-4e2b-a10a-1609cd452405/30152618198.pdf, https://uploads.strikinglycdn.com/files/e456f961-518c-4940-94a6-4c5cd6e67ec3/poguposugik.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 4 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1064 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.85
- 23.11.37.157
- 20.190.167.150
- 52.230.60.54 SG · Singapore · AS8075 Microsoft Corporation
- 150.171.22.17
- 23.33.238.178
- 52.110.12.21 AU · Sydney · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.171
- 192.168.122.113
- 23.221.134.22
- 85.210.196.11 GB · London · AS8075 Microsoft Limited
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://baarspo.ru/strik?utm_term=armitron+wr165ft+set+time
- https://uploads.strikinglycdn.com/files/3fd8c70c-71c4-4e2b-a10a-1609cd452405/30152618198.pdf
- https://uploads.strikinglycdn.com/files/e456f961-518c-4940-94a6-4c5cd6e67ec3/poguposugik.pdf
- http://liko-sneakers.com/61776733774wxhst.pdf
- http://vutagefen.epizy.com/wobasizirenasizimip.pdf
- https://21a67f6d-2aea-439f-a910-ed4feb6be009.filesusr.com/ugd/173616_2535a92c4bcc4f67857a00368b709b67.pdf?index=true
- http://seviridotif.epizy.com/93734178784.pdf
- https://4c2674ec-1430-4cec-a455-d6a35d10586e.filesusr.com/ugd/38955b_2a692281ab4d40599a66e35200ec0b87.pdf?index=true
- https://uploads.strikinglycdn.com/files/466678a7-69cc-4a93-a462-256d62aad564/what_happens_if_your_license_expires_during_covid_19.pdf
- http://vobulag.rf.gd/kugamamazosifufo.pdf
- http://form-copyrightservices.com/receptores_nicotinicos_n1_n2hd490.pdf
- http://shoop-fp.ru/321737364999hct3.pdf
- http://lazazowoj.epizy.com/16690084518.pdf
- https://91ca87c2-c493-4616-adaa-fbcec45394e1.filesusr.com/ugd/6116da_92e33d6e72114c7a96fe237fb66aca19.pdf?index=true
- https://uploads.strikinglycdn.com/files/c7b0f966-f711-4d62-bfcc-9261614fb624/jamasonuruvopimamago.pdf
- https://uploads.strikinglycdn.com/files/3a4abed6-b216-44e9-b661-3f60a5e4b8aa/how_to_program_baofeng_uv-5r_with_computer.pdf
- https://64e18f06-8a0e-4dc1-8427-9dd81b4bff36.filesusr.com/ugd/baa514_4bc003d9129b43c293e935ab50136350.pdf?index=true
- https://uploads.strikinglycdn.com/files/b1d6803a-4331-4289-a3d2-6722aeee9ca8/cradlepoint_ibr600_user_manual.pdf
- https://c46c713f-5e69-4c64-aad4-d86f29440f76.filesusr.com/ugd/957c7b_c7eca54cdfd0472186bbb0cc0135fb89.pdf?index=true
- https://uploads.strikinglycdn.com/files/1b8d4005-6d78-4481-9e60-906ad2ce297f/38815842913.pdf
- http://medojowibapij.epizy.com/3252090250.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- baarspo.ru
- uploads.strikinglycdn.com
- liko-sneakers.com
- vutagefen.epizy.com
- 21a67f6d-2aea-439f-a910-ed4feb6be009.filesusr.com
- seviridotif.epizy.com
- 4c2674ec-1430-4cec-a455-d6a35d10586e.filesusr.com
- form-copyrightservices.com
- shoop-fp.ru
- lazazowoj.epizy.com
- 91ca87c2-c493-4616-adaa-fbcec45394e1.filesusr.com
- 64e18f06-8a0e-4dc1-8427-9dd81b4bff36.filesusr.com
- c46c713f-5e69-4c64-aad4-d86f29440f76.filesusr.com
- medojowibapij.epizy.com
- www.w3.org
- purl.org
- ns.adobe.com
- vobulag.rf.gd
Embedded IP addresses
- 52.230.60.54
- 52.110.12.21
- 4.230.171.124
- 85.210.196.11
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report