MALICIOUS — d2fcbf0d9dfafafc225616ec0614f37adbd2c9b70c862bed27b737e008c509b2
MALICIOUS — d2fcbf0d9dfafafc225616ec0614f37adbd2c9b70c862bed27b737e008c509b2 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100). 5 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
d2fcbf0d9dfafafc225616ec0614f37adbd2c9b70c862bed27b737e008c509b2 - SHA-1:
5ef86240b82e56ade111305eb0b740a74c8a71d7 - MD5:
014234cae44275e6b4db27dff5ea7cd6 - ssdeep:
1536:6L544DZHM6Hk9qjlpkV0XnAzPbFncGNUjY8VX+PHuuwDkuf3rqnCowm:8449HM196lp/XcFcGoV6HuuwDkufOCc - TLSH:
T10239D0F79157DE4C7A97DB932DA911AE6099D388B1399F801089375CC8BCABDBF20440 - Submitted as: d2fcbf0d9dfafafc225616ec0614f37adbd2c9b70c862bed27b737e008c509b2
- File type: pdf · Size: 85514 bytes
- Verdict: malicious (100/100)
Detections (5 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!014234CAE442
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/cc3f1972-3bed-4463-91bf-96257637c43a/bosch_silence_plus_44_dba_water_not_draining.pdf - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PDF/Phish-FAB!014234CAE442 (rule
PDF/Phish-FAB!014234CAE442) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://druttle.ru/strik?utm_term=iq+test+questions+with+answers+pdf+in+tamil, https://cdn.sqhk.co/figegixo/xjb5HBG/the_silent_age_chapter_3.pdf, https://uploads.strikinglycdn.com/files/cc3f1972-3bed-4463-91bf-96257637c43a/bosch_silence_plus_44_dba_water_not_draining.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 11 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1011 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- ntp.ubuntu.com
- desktop-hsgcbep(2)._dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
- 20.190.142.164
- 52.230.59.222 SG · Singapore · AS8075 Microsoft Corporation
- 52.123.252.230 AU · Sydney · AS8075 Microsoft Corporation
- 23.33.238.178
- 52.110.12.40 AU · Sydney · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.207
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://druttle.ru/strik?utm_term=iq+test+questions+with+answers+pdf+in+tamil
- https://cdn.sqhk.co/figegixo/xjb5HBG/the_silent_age_chapter_3.pdf
- https://uploads.strikinglycdn.com/files/cc3f1972-3bed-4463-91bf-96257637c43a/bosch_silence_plus_44_dba_water_not_draining.pdf
- https://uploads.strikinglycdn.com/files/39cf598e-a786-4c97-9c32-a75124125988/daxekitonakiji.pdf
- http://4gusevshop.space/degabupixizuvimupitublexx0.pdf
- https://cdn.sqhk.co/dagozuwemep/gitjjhf/tusubanazufidelu.pdf
- https://cdn.sqhk.co/riwifesineji/xhfigRl/rolling_stones_t_shirt_primark.pdf
- http://bugilinupapud.mygamesonline.org/48599052188.pdf
- https://cdn.sqhk.co/tilesoxeg/idibjhJ/mendeley_apa_citation_guide.pdf
- https://static.s123-cdn-static.com/uploads/4404975/normal_5ff37d6000c7a.pdf
- https://uploads.strikinglycdn.com/files/6a97b378-4dd0-40e1-a329-9322913a8c39/how_long_do_ryobi_40v_batteries_last.pdf
- https://cdn.sqhk.co/sugezigo/ajhWicv/6400787136.pdf
- http://lovelyhouse.online/35973459038oyl9q.pdf
- https://cdn.sqhk.co/bavomizobe/ifE1ges/xegozijonumovesufejano.pdf
- https://cdn.sqhk.co/zeritogekuja/diaFhgD/droplist_streetwear_sneaker_release_information.pdf
- https://uploads.strikinglycdn.com/files/7a02f517-731e-4728-a745-cc0dfb9e36d8/samsung_smart_care_vrt_plus_washer_ur_code.pdf
- https://cdn.sqhk.co/kojivitew/3hihjha/assistant_acquisition_manager_interview_questions_and_answers.pdf
- https://cdn.sqhk.co/tifatuju/7tVibnh/iron_bottle_opener_anniversary.pdf
- http://rokuboxajiga.medianewsonline.com/xexirisikaja.pdf
- https://cdn-cms.f-static.net/uploads/4458827/normal_5fd2c3a8cb379.pdf
- http://zalatikewal.atwebpages.com/belajar_bahasa_arab_bagi_pemula.pdf
- https://uploads.strikinglycdn.com/files/6bb3f7f1-4af9-4c64-acd8-27a300ffdd9b/timex_clock_radio_manual_dual_alarm.pdf
- https://cdn.sqhk.co/jibezilesu/gizgdgf/paintball_guns_price_ebay.pdf
- https://static.s123-cdn-static.com/uploads/4403688/normal_6004901151354.pdf
- http://xojuxelase.medianewsonline.com/aleko_gate_opener_installation.pdf
Embedded domains
- druttle.ru
- cdn.sqhk.co
- uploads.strikinglycdn.com
- 4gusevshop.space
- bugilinupapud.mygamesonline.org
- static.s123-cdn-static.com
- lovelyhouse.online
- rokuboxajiga.medianewsonline.com
- cdn-cms.f-static.net
- zalatikewal.atwebpages.com
- xojuxelase.medianewsonline.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 74.179.71.159
- 20.184.175.23
- 72.145.35.96
- 52.230.59.222
- 52.123.252.230
- 52.110.12.40
- 4.230.171.124
- 74.178.76.54
- 104.46.162.229
- 20.42.179.192
- 20.42.65.91
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report