MALICIOUS — nejomereguv.pdf
MALICIOUS — nejomereguv.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
0a55ca46871a3ca5f6804432a7070319bd48c3d01d9e16bde56239ca18a96f6f - SHA-1:
b63dfce9bd59c3f46c47e9e7d63f886205f8bb06 - MD5:
2aa90cfdba4f5419c9108273224217f0 - ssdeep:
1536:Cofp4LD7vMj8a4sEJ1RjV5nGl7XAAXqusleWepOZrWu11Svq4cT:54L3MoiEbRjV5GNXAAXYlHZr11+qd - TLSH:
T18937BFF3A29BDE0CBB9B9F435DD61168A44FD644A272EB904088B66CC57C63DEF10601 - Submitted as: nejomereguv.pdf
- File type: pdf · Size: 75861 bytes
- Verdict: malicious (98/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Embedded link rated suspicious by URL analysis: http://www.hotel-margherita.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b891d8dad6e---69412937415.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://www.chinahkcarplate.com/wp-content/plugins/formcraft/file-upload/server/content/files/161077b8313bc8---41541754239.pdf, http://lakesnwoodskerala.com/uploads/file/gozigativimamatojibo.pdf, http://wbbray.com/wp-content/plugins/formcraft/file-upload/server/content/files/160acf53b5488f---81443128875.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 6 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
992 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- WORKGROUP
- desktop-hsgcbep
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- 224.0.0.251
- ff02::fb
- 10.240.0.1
- ff02::16
- 169.254.255.255
- 185.125.190.56
- 224.0.0.22
- 91.189.91.157
- ff02::1
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.tlgIkITzVB -
71bc3da43958baec2ec4a2f5db474e4259386c98f39fb0228025ba4e3399ca76
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/ngfLrbzwjls/uplcv?utm_term=pro+forma+projections
- http://www.chinahkcarplate.com/wp-content/plugins/formcraft/file-upload/server/content/files/161077b8313bc8---41541754239.pdf
- http://lakesnwoodskerala.com/uploads/file/gozigativimamatojibo.pdf
- http://wbbray.com/wp-content/plugins/formcraft/file-upload/server/content/files/160acf53b5488f---81443128875.pdf
- http://www.hotel-margherita.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b891d8dad6e---69412937415.pdf
- http://wjvanderheidedienstverlening.nl/uploads/file/xafinivonibara.pdf
- https://www.tonygssoulfood.com/wp-content/plugins/super-forms/uploads/php/files/c19956f4894b31eb845af8eace08a4cb/82072730918.pdf
- http://bogieclassof67.com/clients/71235/File/24021090524.pdf
- http://linker-apps.com/files/6627688181.pdf
- http://www.caribbeandentist.com/wp-content/plugins/formcraft/file-upload/server/content/files/160853b6a64135---94861401019.pdf
- https://www.scanworld.se/wp-content/plugins/formcraft/file-upload/server/content/files/160acaf599e273---lewegovox.pdf
- http://cornucopiafrederick.com/uploads/files/zexusisegedo.pdf
- http://barrarioservicos.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1608cbbde832b4---11360279159.pdf
- http://www.gaviprintpack.com/wp-content/plugins/formcraft/file-upload/server/content/files/16096d57e95deb---janalesosenikopajuketux.pdf
- http://studiopignotti.it/userfiles/files/5558471128.pdf
- https://csmgh.net/pevron/www/img/file/59731116314.pdf
- https://beatmuellerfoto.ch/userfiles/files/mimunikozarigazukepelu.pdf
- http://oppedisanorobertosrl.com/userfiles/files/18799466911.pdf
- http://highdeal.linkeo.net/ckfinder/userfiles/files/titawizegavalikatavarom.pdf
- http://jrpst.pl/userfiles/file/86621623089.pdf
- http://logisticsnetworks.net/ckfinder/userfiles/files/11876348341.pdf
- https://manenshop.com/upload/files/79466703432.pdf
- https://lastcallslc.com/wp-content/plugins/super-forms/uploads/php/files/ba084553a0ad305deadbde15cdda8620/80011879327.pdf
- https://www.bountyvacation.com/wp-content/plugins/formcraft/file-upload/server/content/files/160f4a134a2580---5558994368.pdf
- http://makaeximworld.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608059322f798---tirivopeneliwu.pdf
Embedded domains
- feedproxy.google.com
- www.chinahkcarplate.com
- lakesnwoodskerala.com
- wbbray.com
- www.hotel-margherita.com
- wjvanderheidedienstverlening.nl
- www.tonygssoulfood.com
- bogieclassof67.com
- linker-apps.com
- www.caribbeandentist.com
- www.scanworld.se
- cornucopiafrederick.com
- barrarioservicos.com.br
- www.gaviprintpack.com
- studiopignotti.it
- csmgh.net
- beatmuellerfoto.ch
- oppedisanorobertosrl.com
- highdeal.linkeo.net
- jrpst.pl
- logisticsnetworks.net
- manenshop.com
- lastcallslc.com
- www.bountyvacation.com
- makaeximworld.com
Embedded IP addresses
- 74.178.240.61
- 172.172.255.218
- 74.178.232.29
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report