MALICIOUS — 85298078315.pdf
MALICIOUS — 85298078315.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
1f42f95fcd90d36b786e8557fc3bb5a0d060e6af96495ac1bb9a3ea918b917bb - SHA-1:
a9c8a8b694216b12e38601944158082e1ecd59c9 - MD5:
08d2d20ea8c51596835de3c06e5a8063 - ssdeep:
1536:fAdMIOleJT/Kkje8xCIRtMsmXpWVoUVa80k/TWapOn7Pk1jABvfT:dIOk/KkK+CIRt3mwxJn/cn78j2 - TLSH:
T16239D0F31197DE9C328ACB03BAF511A8A489E6CC6122DDA05589773CD47C2BEBF10941 - Submitted as: 85298078315.pdf
- File type: pdf · Size: 84946 bytes
- Verdict: malicious (99/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded link rated suspicious by URL analysis: http://conflictfreeelectronics.com/ourprojects/chowki/UserFiles/renuka/file/29816351926.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://mebelpozakazu.ru/wp-content/plugins/super-forms/uploads/php/files/a558a0a821a8c818cedde0a5d15f8ae4/83650375689.pdf, https://nikosdimos.gr/userfiles/file/tatolo.pdf, http://niszczeniewaw.pl/userfiles/file/69779246388.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 6 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
985 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 250.255.255.239.in-addr.arpa
- ff02::1:3
- 224.0.0.252
- 169.254.255.255
- 10.240.0.255
- 10.240.0.1
- 224.0.0.251
- ff02::fb
- 135.233.95.144 US · Des Moines · AS8075 Microsoft Limited
- 91.189.91.157
- ff02::1:2
- ff02::16
- 224.0.0.22
- 239.255.255.250
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.iOc0MScxFX -
db197a600570983233f8c66f86184284bdd27632c6f7408214f7cee798b50e58
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/1xuhb7AK25c/uplcv?utm_term=12th+auditing+book+in+english+pdf
- https://mebelpozakazu.ru/wp-content/plugins/super-forms/uploads/php/files/a558a0a821a8c818cedde0a5d15f8ae4/83650375689.pdf
- https://nikosdimos.gr/userfiles/file/tatolo.pdf
- http://niszczeniewaw.pl/userfiles/file/69779246388.pdf
- http://conflictfreeelectronics.com/ourprojects/chowki/UserFiles/renuka/file/29816351926.pdf
- http://kondicionery-krasnogorsk.ru/upload_picture/file/66286664462.pdf
- http://www.asap-recruitment.net/upload/file/50669109542.pdf
- http://transsnabstroy.com/userfiles/file/mebusaxerulapabitir.pdf
- https://www.bountyvacation.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b7384283265---mexukemojotaxuzuj.pdf
- https://www.sesc.com.ua/wp-content/plugins/super-forms/uploads/php/files/usq6k6kokv6a6f5qbq7k5iiv87/xefukejonixi.pdf
- http://chicagohalo.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a03e20ec660---83700955669.pdf
- http://bolshunoff.ru/images/wysiwyg/file/70921743583.pdf
- https://betonwerkendejonge.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16091afce3bb78---gibujejogiruzeburejujubut.pdf
- http://tks-forever.com/upload/2021/07/23/file/2126026838.pdf
- http://israel-aliya.com/wp-content/plugins/super-forms/uploads/php/files/719af5b164be0ad9e5a7534babab243a/kotejalusefomiwolubupe.pdf
- http://homestationrealty.com/userfiles/files/taguwoxaxesodepodepu.pdf
- https://g3az.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609bf81f6fdbf---25620071975.pdf
- http://whkmradio.com/userfiles/file/mubasuninilaviremobabelik.pdf
- http://autodilykanka.cz/cmsimple/images/file/18796917198.pdf
- https://clubforeducation.com/FCKeditor/userfiles/file/telowid.pdf
- https://washlounge.in/ckfinder/userfiles/files/rotum.pdf
- https://www.sensormaticltd.com/app/templates/js/ckfinder/userfiles/files/jinugawu.pdf
- http://t-p-fortune.com/userfiles/file/48094417475.pdf
- http://vietxetai.com/wp-content/plugins/super-forms/uploads/php/files/d8e616t5id3k048rse5tf4bsii/24335360945.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- mebelpozakazu.ru
- niszczeniewaw.pl
- conflictfreeelectronics.com
- kondicionery-krasnogorsk.ru
- www.asap-recruitment.net
- transsnabstroy.com
- www.bountyvacation.com
- www.sesc.com.ua
- chicagohalo.com
- bolshunoff.ru
- betonwerkendejonge.nl
- tks-forever.com
- israel-aliya.com
- homestationrealty.com
- g3az.com
- whkmradio.com
- clubforeducation.com
- washlounge.in
- www.sensormaticltd.com
- t-p-fortune.com
- vietxetai.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 135.233.95.144
- 34.160.111.145
- 57.154.63.210
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report