MALICIOUS — cf26317dac14437014333945753ecd06a3bba4e8be1fb2ea437d31d494f9ec68
MALICIOUS — cf26317dac14437014333945753ecd06a3bba4e8be1fb2ea437d31d494f9ec68 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
cf26317dac14437014333945753ecd06a3bba4e8be1fb2ea437d31d494f9ec68 - SHA-1:
5c96b02b552f7a6b4896f8fa1dbd2475bbd091ec - MD5:
bb7e6e9e2e30d22ca0e3aea05cd9c16c - ssdeep:
1536:434bbidrWLiKmpOxaBJwotArbTl6Dmn2u24VGJQ2WwpOS9W/S4q6kDn:lXiYm8xaBJcfADmn72435Scu - TLSH:
T11D3AD0F33197DD5C7686CB0759BA16A9284DE7882162EB909188B63CC5BC5FEBF00502 - Submitted as: cf26317dac14437014333945753ecd06a3bba4e8be1fb2ea437d31d494f9ec68
- File type: pdf · Size: 99604 bytes
- Verdict: malicious (98/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://123kozijnofferte.nl/wp-content/plugins/super-forms/uploads/php/files/314f50fcefd4f7c634d118ee2c452fee/jipoxese.pdf, https://0922.sproname.com/files/userfiles/files/sobatefaru.pdf, http://www.perlodrink.com/documents/wuwuwikuzuvijuritu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 7 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1033 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 192.168.122.106
- 23.40.52.85
- 23.11.37.157
- 20.190.142.164
- 52.123.252.240 AU · Sydney · AS8075 Microsoft Corporation
- 23.198.40.44
- 52.110.12.3 AU · Sydney · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.173
- 172.215.188.225 US · San Antonio · AS8075 Microsoft Limited
- 23.40.52.174
- 20.184.175.6 US · San Jose · AS8075 Microsoft Corporation
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- http://feedproxy.google.com/~r/Xvkpad/~3/tgwjJlsMqHc/uplcv?utm_term=classic+wow+rogue+pre+bis
- https://123kozijnofferte.nl/wp-content/plugins/super-forms/uploads/php/files/314f50fcefd4f7c634d118ee2c452fee/jipoxese.pdf
- https://0922.sproname.com/files/userfiles/files/sobatefaru.pdf
- http://www.perlodrink.com/documents/wuwuwikuzuvijuritu.pdf
- http://britishcytology.org.uk/ckfinder/userfiles/files/15406460563.pdf
- https://repairbase.net/FCKeditor/editor/filemanager/connectors/php/images/file/litavabuboguseli.pdf
- http://betheaskssd.com/flash/betheaskssd.com/file/xubezijur.pdf
- https://fsreloading.com/userfiles/files/35456364241.pdf
- https://santaclara.com/wysiwygfiles/file/fudusuvi.pdf
- https://dom4m.de/userfiles/files/wowaronama.pdf
- http://compow.net/ckfinder/userfiles/files/dezowolotofanasa.pdf
- http://getawaynewzealand.co.nz/wp-content/plugins/formcraft/file-upload/server/content/files/16162b24bd47b2---91535257086.pdf
- http://sbkf.org/files/files/wudadijegizukudur.pdf
- http://blackivy.pl/userfiles/file/timunaso.pdf
- http://dekobonner.de/userfiles/file/dixitoretiguwiba.pdf
- https://petroblend.com/wp-content/plugins/formcraft/file-upload/server/content/files/16160579148b71---70282720491.pdf
- http://dury114.com/userData/ebizro_board/file/21384962731.pdf
- https://pcetravel.com/files/file/43468726965.pdf
- http://legalinet.eu/userfiles/files/xunimamakuvegaj.pdf
- https://capitalsyndic.com/userfiles/file/11050264168.pdf
- http://alltechsro.cz/files/dimex.pdf
- https://www.limratechnologies.net/wp-content/plugins/formcraft/file-upload/server/content/files/1616536f244fac---69111941163.pdf
- https://rcvizovice.cz/ckfinder/userfiles/files/11430299638.pdf
- https://www.avenueroadadvertising.com/wp-content/plugins/formcraft/file-upload/server/content/files/1615a68225e8d8---41689427809.pdf
- http://www.chp.pl/ckfinder/userfiles/files/rezusel.pdf
Embedded domains
- feedproxy.google.com
- 123kozijnofferte.nl
- 0922.sproname.com
- www.perlodrink.com
- britishcytology.org.uk
- repairbase.net
- betheaskssd.com
- fsreloading.com
- santaclara.com
- dom4m.de
- compow.net
- sbkf.org
- blackivy.pl
- dekobonner.de
- petroblend.com
- dury114.com
- pcetravel.com
- legalinet.eu
- capitalsyndic.com
- www.limratechnologies.net
- www.avenueroadadvertising.com
- www.chp.pl
- cheapneasytrafficschool.com
- combatkuntao.com
- woonhuislift.info
Embedded IP addresses
- 40.84.85.40
- 172.172.255.216
- 52.123.252.240
- 52.110.12.3
- 4.230.171.124
- 172.215.188.225
- 20.184.175.6
File paths
- z:\c#
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report