MALICIOUS — f01bca5e1b34614780875b9294f2f7009c0893dc395b7321e636dc2dab5d7180
MALICIOUS — f01bca5e1b34614780875b9294f2f7009c0893dc395b7321e636dc2dab5d7180 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f01bca5e1b34614780875b9294f2f7009c0893dc395b7321e636dc2dab5d7180 - SHA-1:
1921fcb8d226e8ef935e03021757e6fcd2709707 - MD5:
c2bfc06b5a20bb31feb78c288c02fc4a - ssdeep:
1536:1Mk58OaM/C4hLemNB1ZbcSwFD1Ey0+BCnyUmWTgXXcW6pOu2a4Mt72drz:SO1aqeY1ZSmyXU7CVu2axt6d/ - TLSH:
T14539D0F330D7DDDC7B4B9F8369AA019CB08AE7846263DA445188B6ACC1785BDBF10521 - Submitted as: f01bca5e1b34614780875b9294f2f7009c0893dc395b7321e636dc2dab5d7180
- File type: pdf · Size: 91997 bytes
- Verdict: malicious (99/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 8 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://chcial.ru/uplcv?utm_term=programa+oficial+fallas+2019+pdf, http://sanchariglobal.com/userfiles/file/dilol.pdf, https://frontiersneurophotonics.org/wp-content/plugins/formcraft/file-upload/server/content/files/1/1607c7ee191a74---97495330543.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1066 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- _dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- 23.40.52.85
- 23.11.37.157
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://chcial.ru/uplcv?utm_term=programa+oficial+fallas+2019+pdf
- http://sanchariglobal.com/userfiles/file/dilol.pdf
- https://frontiersneurophotonics.org/wp-content/plugins/formcraft/file-upload/server/content/files/1/1607c7ee191a74---97495330543.pdf
- https://loan-financial.com/wp-content/plugins/super-forms/uploads/php/files/f35b015288158e9e9a5a89061e7230c8/178117077.pdf
- http://www.petersmetalstitching.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/1609c667304cd1---burejogilegonuxagupedaj.pdf
- https://www.cibaospalaser.com/wp-content/plugins/super-forms/uploads/php/files/gecpf4fn5ga3kta4saaqkghjf2/88210451067.pdf
- https://avgdesign.com/userfiles/file/86928122880.pdf
- https://www.pharmawell.eu/ckfinder/userfiles/files/37679657497.pdf
- https://iamluno.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bb27669ec76---46049485800.pdf
- http://fra2ange.it/userfiles/files/73773203840.pdf
- http://sro52.ru/uploads/files/40051367216.pdf
- http://aimic.com/userfiles/file/46988971961.pdf
- https://amatnieks.lv/pictures/image/sonodawokudasikaf.pdf
- https://rittenhousesmiles.com/wp-content/plugins/super-forms/uploads/php/files/66b89e8b1f710305eb242ce0cd039d90/37065801669.pdf
- http://www.goataxiservice.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c92e3b77a88---82133144333.pdf
- https://www.temsilcisitesi.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609d8d69490de---ronojujavebaxibirexem.pdf
- http://svs-pm.com/wp-content/plugins/formcraft/file-upload/server/content/files/16090914ee7ddb---firogokolelapezasubutib.pdf
- https://thepetrichortouch.com/wp-content/plugins/super-forms/uploads/php/files/9kfmdn9sd0oetquk0c9223d16o/vupirarabizida.pdf
- https://robinio.de/wp-content/plugins/super-forms/uploads/php/files/ki995j780tlgvujk4ppr5i3r9r/90053830479.pdf
- http://elitaliaweb.it/upload/file/78586495002.pdf
- http://rustproofingottawa.com/userfiles/file/29010534891.pdf
- http://softwarefactory.nl/images/file/63484034033.pdf
- http://xn--zb0by3yusal20ak5lcidnwigi.com/ckfinder/userfiles/files/1630294287.pdf
- https://spa-salon.ru/ckfinder/userfiles/files/rosivukuwisiserafazidup.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- fu.it
- chcial.ru
- sanchariglobal.com
- frontiersneurophotonics.org
- loan-financial.com
- www.petersmetalstitching.co.za
- www.cibaospalaser.com
- avgdesign.com
- www.pharmawell.eu
- iamluno.com
- fra2ange.it
- sro52.ru
- aimic.com
- rittenhousesmiles.com
- www.goataxiservice.com
- www.temsilcisitesi.com
- svs-pm.com
- thepetrichortouch.com
- robinio.de
- elitaliaweb.it
- rustproofingottawa.com
- softwarefactory.nl
- xn--zb0by3yusal20ak5lcidnwigi.com
- spa-salon.ru
- www.w3.org
Embedded IP addresses
- 72.145.35.102
- 52.110.12.31
- 4.144.132.114
- 4.230.171.124
- 48.211.4.16
- 92.223.78.30
- 72.154.7.107
- 20.42.65.90
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report