MALICIOUS — d940a761661d64a4e2f44631a11905ccbf656c46202f9e29d6bdf2de221cab4b
MALICIOUS — d940a761661d64a4e2f44631a11905ccbf656c46202f9e29d6bdf2de221cab4b is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100). 5 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
d940a761661d64a4e2f44631a11905ccbf656c46202f9e29d6bdf2de221cab4b - SHA-1:
6a2a2f0b64cc45f637a39a170646411b0e59e8bf - MD5:
600c1562c2c4ce85f8ce00645012d6f8 - ssdeep:
1536:zGhh7Ak46DPyGtyqVEqSQdcwi4gXCOtTJX7c70hWqDeO5b4XQyCCwJ:qIF6DNt9G9QdcwcXCORxc70hhV5bZyY - TLSH:
T1A639E1F3918BEC8DBA865B4B6DBE255C6099D2C42136CA6455C47B2CC83C3FF7924A10 - Submitted as: d940a761661d64a4e2f44631a11905ccbf656c46202f9e29d6bdf2de221cab4b
- File type: pdf · Size: 88162 bytes
- Verdict: malicious (100/100)
Detections (5 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!600C1562C2C4
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PDF/Phish-FAB!600C1562C2C4 (rule
PDF/Phish-FAB!600C1562C2C4) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 11 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded link rated suspicious by URL analysis: https://cdn-cms.f-static.net/uploads/4413374/normal_601998c203720.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://midufefew.ru/strik?utm_term=plantronics+m180+pairing+mode+plt, https://nebobaxewakizix.weebly.com/uploads/1/3/1/6/131637309/xekasigirifi-jukexuviv.pdf, https://cdn-cms.f-static.net/uploads/4413374/normal_601998c203720.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in Acrobat.exe (pid 8572) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
1079 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- 23.40.52.85
- 23.11.37.157
- 20.190.167.65
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://midufefew.ru/strik?utm_term=plantronics+m180+pairing+mode+plt
- https://nebobaxewakizix.weebly.com/uploads/1/3/1/6/131637309/xekasigirifi-jukexuviv.pdf
- https://cdn-cms.f-static.net/uploads/4413374/normal_601998c203720.pdf
- https://64e18f06-8a0e-4dc1-8427-9dd81b4bff36.filesusr.com/ugd/baa514_4f2d207322a342a097717601cc62eb88.pdf?index=true
- https://wobakasufafe.weebly.com/uploads/1/3/2/6/132682589/75f0340622359.pdf
- http://tesuzegijibonu.epizy.com/favutazite.pdf
- https://98be45bc-63b9-4117-aff7-84a3d4f2c4a0.filesusr.com/ugd/90c678_0752b3bea1c14c5cb8c5fb0436907cb0.pdf?index=true
- https://0e67983c-e844-40c9-b604-97311ec94efe.filesusr.com/ugd/6e13d9_1f3c5f7a577049fa89d21ce0e2a18e71.pdf?index=true
- https://51f47fa2-20f7-4ec4-bb91-8ae4aee689b4.filesusr.com/ugd/917232_267002dfb6a04929af3e2a9ed57794d2.pdf?index=true
- https://203aa715-7352-46b1-b16b-5d0aeeaa27a2.filesusr.com/ugd/0582e0_d4a93397159f4dab9e24976057b6c04a.pdf?index=true
- https://zisifogadudup.weebly.com/uploads/1/3/4/7/134765868/napolu-vogobil.pdf
- http://misezofet.epizy.com/how_to_start_whirlpool_quiet_partner_iii.pdf
- https://cdn-cms.f-static.net/uploads/4367289/normal_6029cd5e96493.pdf
- https://814cba0f-f649-4223-bfe6-7884e6e02b9d.filesusr.com/ugd/c1108c_dee548bbbd9146368c0808ebf82074d4.pdf?index=true
- http://gidepajujida.rf.gd/shareit_app_by_play_store.pdf
- http://tixuveji.epizy.com/a_ha_mtv_unplugged_summer_solstice.pdf
- http://degimoto.22web.org/zama_carburetor.pdf
- http://sujuxokilir.epizy.com/customer_details_template_word.pdf
- https://6d428a25-da86-44fa-8f13-5b0f09742281.filesusr.com/ugd/3649d2_c0d2f2b6dc204ae0b4274a7bb0caecd5.pdf?index=true
- https://vabekozel.weebly.com/uploads/1/3/4/4/134487462/1365812.pdf
- https://penixosifa.weebly.com/uploads/1/3/1/4/131482878/doliw.pdf
- http://banujal.iblogger.org/chhaila_bihari_bol_bam_song.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- midufefew.ru
- nebobaxewakizix.weebly.com
- cdn-cms.f-static.net
- 64e18f06-8a0e-4dc1-8427-9dd81b4bff36.filesusr.com
- wobakasufafe.weebly.com
- tesuzegijibonu.epizy.com
- 98be45bc-63b9-4117-aff7-84a3d4f2c4a0.filesusr.com
- 0e67983c-e844-40c9-b604-97311ec94efe.filesusr.com
- 51f47fa2-20f7-4ec4-bb91-8ae4aee689b4.filesusr.com
- 203aa715-7352-46b1-b16b-5d0aeeaa27a2.filesusr.com
- zisifogadudup.weebly.com
- misezofet.epizy.com
- 814cba0f-f649-4223-bfe6-7884e6e02b9d.filesusr.com
- tixuveji.epizy.com
- degimoto.22web.org
- sujuxokilir.epizy.com
- 6d428a25-da86-44fa-8f13-5b0f09742281.filesusr.com
- vabekozel.weebly.com
- penixosifa.weebly.com
- banujal.iblogger.org
- www.w3.org
- purl.org
- ns.adobe.com
- gidepajujida.rf.gd
- x2.c.lencr.org
Embedded IP addresses
- 40.84.85.40
- 203.26.79.13
- 52.110.12.21
- 52.110.12.2
- 4.230.171.124
- 20.42.179.204
- 172.64.154.167
- 20.247.184.197
- 20.42.65.91
- 172.215.188.232
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report