MALICIOUS — d1ef5c4358f1714eeefb5c02c3009d2b681fc52f2204bd5665dede03579182fa
MALICIOUS — d1ef5c4358f1714eeefb5c02c3009d2b681fc52f2204bd5665dede03579182fa is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d1ef5c4358f1714eeefb5c02c3009d2b681fc52f2204bd5665dede03579182fa - SHA-1:
4099dc4eb5e06d60bcf9242277d8b53f753b41dc - MD5:
3f602261b7c519d8e658a7b22f6e5d6c - ssdeep:
1536:X8P0VfHTPaxBwbKhBVDDP836Gy5hrJh9/XpVygzpHdXWkNpOPaWSgP+9vces2nRS:xRHePwbK/1DP8Kdh9pV9Hd4P/Y0es2RS - TLSH:
T1153AE0B320ABDC4CB78B9F0359E541ADB59AE3842133DB58018CB35C89BC6BEBD11552 - Submitted as: d1ef5c4358f1714eeefb5c02c3009d2b681fc52f2204bd5665dede03579182fa
- File type: pdf · Size: 96453 bytes
- Verdict: malicious (99/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 11 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://garglob.ru/uplcv?utm_term=trillville+some+cut+clean, https://mosconi.net/userfiles/file/86642889478.pdf, http://aliancegroup.su/wp-content/plugins/formcraft/file-upload/server/content/files/16084e6fe1bbb5---tijamipubinifike.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1037 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ntp.ubuntu.com
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- 23.40.52.85
- 23.11.37.157
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://garglob.ru/uplcv?utm_term=trillville+some+cut+clean
- https://mosconi.net/userfiles/file/86642889478.pdf
- http://aliancegroup.su/wp-content/plugins/formcraft/file-upload/server/content/files/16084e6fe1bbb5---tijamipubinifike.pdf
- http://sazjah.com/wp-content/plugins/formcraft/file-upload/server/content/files/160768b9d08300---pelirinitufitonotaj.pdf
- https://www.pietri-automobiles.com/wp-content/plugins/super-forms/uploads/php/files/4vl7ua5s067ddq1ltl7covok10/58928428662.pdf
- http://seibyou-koujien.com/files/files/61790852424.pdf
- http://beergolfers.com/blog/images/file/9165111952.pdf
- http://snookerfootball.eu/wp-content/plugins/formcraft/file-upload/server/content/files/16085ab2f44450---luxajenokejakirodod.pdf
- http://chieusangducphat.com/uploads/userfiles/file/28771691428.pdf
- http://www.scmphotography.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160a79361dc09e---49154716938.pdf
- http://friluftsgruppen.se/wp-content/plugins/formcraft/file-upload/server/content/files/16075b0f964e22---belasixadatatawu.pdf
- https://cosalesrep.com/wp-content/plugins/super-forms/uploads/php/files/fb62850afae4e2caaa0157aba18eddbb/11025365287.pdf
- https://www.ferienhof-schneider.de/wp-content/plugins/formcraft/file-upload/server/content/files/16077bf0ebfcb1---21275998684.pdf
- http://ebslang.net/_UploadFile/Images/file/50927627675.pdf
- https://www.sevgiliyevideo.net/wp-content/plugins/formcraft/file-upload/server/content/files/160af6fc3a2e98---bizogexevozivawa.pdf
- https://jakspravnenapsa.cz/userfiles/file/27432285991.pdf
- https://fishboat.hr/files/mowunopumobodujuxiromi.pdf
- https://www.picmephotoboothhire.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160909d122f80b---kosoripomixivovu.pdf
- http://www.oknookna.pl/wp-content/plugins/formcraft/file-upload/server/content/files/1609137b3ef92e---82011422832.pdf
- http://svenstavik.com/wp-content/plugins/formcraft/file-upload/server/content/files/16098a4b984a35---towopiwuzanagirexamuwe.pdf
- http://massimosusto.eu/userfiles/files/daresinuzo.pdf
- http://www.recetasyconsejos.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c2bcb17fca8---34936256837.pdf
- https://watertorens.nluserfiles/file/zefominimivog.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a84607ba826---rivoxezesuwolariku.pdf
- http://www.nomorcantikjoss.com/file/2816588005.pdf
Embedded domains
- garglob.ru
- mosconi.net
- aliancegroup.su
- sazjah.com
- www.pietri-automobiles.com
- seibyou-koujien.com
- beergolfers.com
- snookerfootball.eu
- chieusangducphat.com
- www.scmphotography.co.uk
- friluftsgruppen.se
- cosalesrep.com
- www.ferienhof-schneider.de
- ebslang.net
- www.sevgiliyevideo.net
- www.picmephotoboothhire.co.uk
- www.oknookna.pl
- svenstavik.com
- massimosusto.eu
- www.recetasyconsejos.com
- www.1000ena.com
- www.nomorcantikjoss.com
- dev.legaladviceme.com
- www.w3.org
- purl.org
Embedded IP addresses
- 85.210.193.152
- 4.247.188.233
- 48.211.4.16
- 40.84.97.4
- 4.230.171.124
- 4.247.188.224
- 52.230.60.54
- 20.42.73.31
- 74.178.76.128
- 20.42.65.91
- 20.42.73.27
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report