MALICIOUS — e9ae40a623d07afc8fe713966097384fedec90825f7cbdd948b2e462d17d7250
MALICIOUS — e9ae40a623d07afc8fe713966097384fedec90825f7cbdd948b2e462d17d7250 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100). 5 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
e9ae40a623d07afc8fe713966097384fedec90825f7cbdd948b2e462d17d7250 - SHA-1:
e79334e9d16cc82e0baeed2b4b165a00cbba1359 - MD5:
d042fb234adaf08c0fc92ae3a69b7d5b - ssdeep:
1536:llUIHI718kztzGvSI59Juxf/TJiY/UnCSt0vjBktnonytVBWpDHv:3UIHI7LiamDuVJis1atowVoj - TLSH:
T13938E0F32127CD4C7A4EAB53B9BA235E60C5D34871366B5100887A7CD0BCABE7D61A40 - Submitted as: e9ae40a623d07afc8fe713966097384fedec90825f7cbdd948b2e462d17d7250
- File type: pdf · Size: 83754 bytes
- Verdict: malicious (100/100)
Detections (5 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!D042FB234ADA
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PDF/Phish-FAB!D042FB234ADA (rule
PDF/Phish-FAB!D042FB234ADA) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 12 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded link rated suspicious by URL analysis: http://firstsecu-paypal.com/14713069500ncvgs.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://mezovuduw.ru/123?utm_term=aditya+birla+life+insurance+premium+receipt, https://xukotonaxi.weebly.com/uploads/1/3/1/4/131453431/9821775.pdf, http://firstsecu-paypal.com/14713069500ncvgs.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (13 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1034 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- _dosvc._tcp.local
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep(3)._dosvc._tcp.local
- ntp.ubuntu.com
- desktop-hsgcbep(4)._dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://mezovuduw.ru/123?utm_term=aditya+birla+life+insurance+premium+receipt
- https://xukotonaxi.weebly.com/uploads/1/3/1/4/131453431/9821775.pdf
- http://firstsecu-paypal.com/14713069500ncvgs.pdf
- https://56148a0a-83a3-4003-94ff-78d3044b7c00.filesusr.com/ugd/6f5f23_cf05a2ffdbfb4a1b9a5d884fd9a7521f.pdf?index=true
- https://pojekemo.weebly.com/uploads/1/3/4/4/134469054/5711927.pdf
- https://luragelekow.weebly.com/uploads/1/3/4/3/134377287/kowolotaze.pdf
- https://cdn.sqhk.co/suvezadamut/iadg2je/80299280403.pdf
- http://kemytbok.xyz/gone_with_the_wind_book_imagesnwo05.pdf
- https://2a009ac4-5770-49f2-ae16-4ce107243443.filesusr.com/ugd/59deca_2e04519e9c894b7ca5ffae05fe71b5c1.pdf?index=true
- https://b20aee1f-b1b7-4e4e-be5e-d884e4ece670.filesusr.com/ugd/10e3af_58e417b260a24ce596ed23b77f7acdf4.pdf?index=true
- https://9db8f275-5044-409a-aa1b-3306d9dda9bd.filesusr.com/ugd/361f4b_54f557cf87fc42289d9b9be5d56697c4.pdf?index=true
- https://lowaribopuvege.weebly.com/uploads/1/3/2/8/132814272/vokubuvamupu.pdf
- https://najovukuno.weebly.com/uploads/1/3/1/4/131453374/dobokade.pdf
- https://cdn.sqhk.co/dolubivo/ffxEiam/rapid_sequence_intubation_guidelines.pdf
- https://4cf2acc4-d143-4013-a78d-f21de0873c4f.filesusr.com/ugd/e4636f_116a172daadb4d7e95ab12fd77e9e027.pdf?index=true
- https://gixovazaviv.weebly.com/uploads/1/3/5/9/135982549/2644428.pdf
- http://autokenn.com/60165268956k80yz.pdf
- http://amin-ukraine.net/a_uma_dada_temperatura_2_mol_de_h2gfadu.pdf
- https://danivuzi.weebly.com/uploads/1/3/2/6/132681213/pevosexisefura_fozunokisazad.pdf
- https://a04ad255-06d6-4b17-97e7-91173d300295.filesusr.com/ugd/6864df_0fedd49b5c4c4e65a8ac7689883750c3.pdf?index=true
- https://6e678f60-abc6-404c-883a-cd1729fdffee.filesusr.com/ugd/e4291f_1052315a307b409aaad0755c0373c80d.pdf?index=true
- http://idslim-italia.site/the_republic_of_tea_detox_green_reviewsiyieo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- mezovuduw.ru
- xukotonaxi.weebly.com
- firstsecu-paypal.com
- 56148a0a-83a3-4003-94ff-78d3044b7c00.filesusr.com
- pojekemo.weebly.com
- luragelekow.weebly.com
- cdn.sqhk.co
- kemytbok.xyz
- 2a009ac4-5770-49f2-ae16-4ce107243443.filesusr.com
- b20aee1f-b1b7-4e4e-be5e-d884e4ece670.filesusr.com
- 9db8f275-5044-409a-aa1b-3306d9dda9bd.filesusr.com
- lowaribopuvege.weebly.com
- najovukuno.weebly.com
- 4cf2acc4-d143-4013-a78d-f21de0873c4f.filesusr.com
- gixovazaviv.weebly.com
- autokenn.com
- amin-ukraine.net
- danivuzi.weebly.com
- a04ad255-06d6-4b17-97e7-91173d300295.filesusr.com
- 6e678f60-abc6-404c-883a-cd1729fdffee.filesusr.com
- idslim-italia.site
- www.w3.org
- purl.org
- ns.adobe.com
- x2.c.lencr.org
Embedded IP addresses
- 72.145.35.96
- 162.159.142.9
- 57.155.104.224
- 4.230.171.124
- 135.232.92.97
- 52.182.141.63
- 104.18.33.89
- 4.144.132.114
- 92.223.78.30
- 20.42.73.28
- 72.153.5.139
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report