MALICIOUS — c21a95f5291b16ed9e1ddec7e20156adeb869180cf4bd7182d0bb1e901842fb4
MALICIOUS — c21a95f5291b16ed9e1ddec7e20156adeb869180cf4bd7182d0bb1e901842fb4 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100). 5 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
c21a95f5291b16ed9e1ddec7e20156adeb869180cf4bd7182d0bb1e901842fb4 - SHA-1:
3de06f04addf32ffd57409984bc0294a50f44274 - MD5:
4ebb1e0de34ef9ce98909cd82a2b362e - ssdeep:
1536:K3Nh6nbj1By9gxrc9AzCw3PEsGKkjIqYLvPxT2OoJcStPwAM:GKbj1By9KrU8X3csasLvPxT2OMzPq - TLSH:
T11238C0F750A7DD4CB6979B436DB721AC2092E3C922339794048C3B6C859C7BE6D20D60 - Submitted as: c21a95f5291b16ed9e1ddec7e20156adeb869180cf4bd7182d0bb1e901842fb4
- File type: pdf · Size: 77372 bytes
- Verdict: malicious (100/100)
Detections (5 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!4EBB1E0DE34E
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4496582/normal_5fd03045790d8.pdf - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PDF/Phish-FAB!4EBB1E0DE34E (rule
PDF/Phish-FAB!4EBB1E0DE34E) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://mezovuduw.ru/strik?utm_term=sketchup+warehouse+2019+free+download, https://cdn.sqhk.co/voguzasijur/Lsjeib3/sudoku_hardest_puzzle_ever.pdf, https://tiwebusimevadeb.weebly.com/uploads/1/3/5/3/135346158/6352000.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 12 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1188 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 162.159.142.9 US · San Francisco · AS13335 Cloudflare, Inc.
- 23.11.37.157
- 20.190.142.166
- 20.184.175.23 US · San Jose · AS8075 Microsoft Corporation
- 52.253.84.76 SG · Singapore · AS8075 Microsoft Corporation
- 52.123.252.233 AU · Sydney · AS8075 Microsoft Corporation
- 52.110.12.3 AU · Sydney · AS8075 Microsoft Corporation
- 23.198.40.44
- 40.84.97.4 US · Boydton · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.115
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://mezovuduw.ru/strik?utm_term=sketchup+warehouse+2019+free+download
- https://cdn.sqhk.co/voguzasijur/Lsjeib3/sudoku_hardest_puzzle_ever.pdf
- https://tiwebusimevadeb.weebly.com/uploads/1/3/5/3/135346158/6352000.pdf
- http://watogoda.mypressonline.com/why_is_norse_mythology_popular.pdf
- http://batofudinub.epizy.com/will_cyberpunk_be_fixed_on_ps4_pro.pdf
- https://static.s123-cdn-static.com/uploads/4496582/normal_5fd03045790d8.pdf
- http://jawunefuda.mygamesonline.org/adventures_of_tom_sawyer_novel.pdf
- https://cdn.sqhk.co/zubavagi/UZlhjWO/gacha_life_2_release_date_android.pdf
- http://rajeziriga.scienceontheweb.net/tuwunututata.pdf
- https://cdn.sqhk.co/letijefa/hbjhicB/9105677526.pdf
- https://uploads.strikinglycdn.com/files/3ae08466-3392-4e77-a9d3-a39a63925a70/sony_icf-c1_service_manual.pdf
- https://uploads.strikinglycdn.com/files/40a347ce-acfa-49bb-be11-c226f50dfa3b/the_shack_vb_winter_wonderland.pdf
- https://uploads.strikinglycdn.com/files/4aeaa008-6917-4458-a3fc-73f9209a4dc4/zugatofabebusotevabene.pdf
- https://vuvuzuvikedatun.weebly.com/uploads/1/3/4/5/134529562/4939684.pdf
- https://cdn-cms.f-static.net/uploads/4409826/normal_604f77795f559.pdf
- http://kopalirigel.mypressonline.com/23401370207.pdf
- http://vebadivikini.rf.gd/12511224744.pdf
- http://ripelavezomosiv.iblogger.org/94345916411.pdf
- http://lowuguja.myartsonline.com/78597299180.pdf
- https://uploads.strikinglycdn.com/files/089190ac-4b9f-4885-b558-820e852a7fd7/what_is_human_environment_interaction_in_geography.pdf
- https://uploads.strikinglycdn.com/files/c6a60482-2edc-444b-96f4-7b3b747b1145/no_game_no_life_season_2.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- mezovuduw.ru
- cdn.sqhk.co
- tiwebusimevadeb.weebly.com
- watogoda.mypressonline.com
- batofudinub.epizy.com
- static.s123-cdn-static.com
- jawunefuda.mygamesonline.org
- rajeziriga.scienceontheweb.net
- uploads.strikinglycdn.com
- vuvuzuvikedatun.weebly.com
- cdn-cms.f-static.net
- kopalirigel.mypressonline.com
- ripelavezomosiv.iblogger.org
- lowuguja.myartsonline.com
- www.w3.org
- purl.org
- ns.adobe.com
- vebadivikini.rf.gd
Embedded IP addresses
- 4.247.188.233
- 162.159.142.9
- 20.184.175.23
- 52.253.84.76
- 52.123.252.233
- 52.110.12.3
- 40.84.97.4
- 4.230.171.124
- 20.184.175.6
- 20.42.65.91
- 20.184.175.13
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report