MALICIOUS — d65a50b9435d2f42b035c0b330300219074f7b91532727209c54fb32f9b3e20b
MALICIOUS — d65a50b9435d2f42b035c0b330300219074f7b91532727209c54fb32f9b3e20b is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100). 5 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d65a50b9435d2f42b035c0b330300219074f7b91532727209c54fb32f9b3e20b - SHA-1:
318bc3c76f00c8accf6a017d6cbe8e38530a7770 - MD5:
88d3f620896885fbd13df20ed4aafa79 - ssdeep:
768:257BpL5mli3rsUQx2akLDNL1MqPWawdfjjylwYSviU1CRDBb9eiMvs:8pl4c4UQzklLh6tjjy4iXRDBb9hMvs - TLSH:
T1A7328DF36197CE0CAA865F079EFA545CA099D2852171FE4080D87A7CD17C9FE7B10921 - Submitted as: d65a50b9435d2f42b035c0b330300219074f7b91532727209c54fb32f9b3e20b
- File type: pdf · Size: 44185 bytes
- Verdict: malicious (97/100)
Detections (5 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish.CFN!MTB
- Emsisoft (Emergency Kit): PDF.Spam.Heur.2
- Trellix Stinger (McAfee): PDF/Phish-TWM!88D3F6208968
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 10 weighted signals:
- Microsoft Defender flagged Trojan:PDF/Phish.CFN!MTB (rule
Trojan:PDF/Phish.CFN!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.2 (rule
PDF.Spam.Heur.2) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PDF/Phish-TWM!88D3F6208968 (rule
PDF/Phish-TWM!88D3F6208968) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://netcdn.xyz/app/406889139/coin-master-spin-ml-game-hack, https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/master-coins-free_GM406889139.pdf, https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/coin-master-pro-hack_GM406889139.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 9 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
987 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.85
- 172.66.2.5 US · San Francisco · AS13335 Cloudflare, Inc.
- 23.11.37.157
- 20.190.167.150
- 20.247.184.197 SG · Singapore · AS8075 Microsoft Corporation
- 150.171.22.17
- 52.110.12.21 AU · Sydney · AS8075 Microsoft Corporation
- 52.110.12.37 AU · Sydney · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.114
- 4.144.132.114 SG · Singapore · AS8075 Microsoft Corporation
- 23.33.238.102
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://netcdn.xyz/app/406889139/coin-master-spin-ml-game-hack
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/master-coins-free_GM406889139.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/coin-master-pro-hack_GM406889139.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/coin-master-free-spins-link-blogspot-today_GM406889139.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/coin-master-free-spins-moonactive_GM406889139.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/minecraft-pe-hack-client_GM479516143.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/daily-free-spin-coin-master-link_GM406889139.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/how-to-change-roblox-username-for-free-2021_GM431946152.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/coin-master-mod-apk-hack_GM406889139.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/coin-master-free-cards_GM406889139.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/free-robux-websites-that-work_GM431946152.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/coin-master-free-spins-apk_GM406889139.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/minecraft-for-laptop-free_GM479516143.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/coin-master-3rd-village-free-2021-gift-card_GM406889139.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/how-to-get-free-robux-com_GM431946152.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/coin-master-free-spins-only_GM406889139.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/roblox-free-exploits_GM431946152.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/free-coin-master-spins-for-today_GM406889139.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/oprewards-robux_GM431946152.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/free-coin-master-cards-link_GM406889139.pdf
- https://shop.mercurytekindo.co.id/ckfinder/userfiles/files/wwwcoin-master-hack-apk_GM406889139.pdf
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- netcdn.xyz
- shop.mercurytekindo.co.id
Embedded IP addresses
- 172.66.2.5
- 20.247.184.197
- 52.110.12.21
- 52.110.12.37
- 4.230.171.124
- 4.144.132.114
- 20.247.184.142
- 4.150.223.108
- 85.210.193.152
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report