MALICIOUS — voful.pdf
MALICIOUS — voful.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100). 2 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
245782fce35cbb671df9e180a4dc7cb89f5a4c8320a50de851ca4e93018ab14f - SHA-1:
af7c2dbb8a3d9a49d825c2de74902b4d63af5169 - MD5:
4f1240cf4ae26ddad99e6a627ca38e39 - ssdeep:
768:FqJgGzpDJpiIh69XdY6bviDj4535cObuaSAmv9Wx1nA9Gg3PxHy+w2MjiN3:pGF9piJSESr9Y1nkGg62wiN3 - TLSH:
T10F316CF36197ED4C39C79F13AEAB2AAE644997485132D750509C6B1CC9BC3BC2F40A21 - Submitted as: voful.pdf
- File type: pdf · Size: 40598 bytes
- Verdict: malicious (97/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 8 weighted signals:
- Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Embedded link rated malicious by URL analysis: https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/09b03b.pdf - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://gettraff.ru/wb?keyword=the%20politics%20of%20power%207th%20edition, https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/metor.pdf, https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/09b03b.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1064 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 224.0.0.251
- ff02::fb
- ff02::1:3
- 224.0.0.252
- 169.254.255.255
- 10.240.0.255
- 239.255.255.250
- 74.178.76.128 IE · Dublin · AS8075 Microsoft Corporation
- ff02::2
- ff02::1:ff4c:1d1d
- ff02::1:ff12:3456
- 255.255.255.255
- ff02::1:2
- ff02::16
- 224.0.0.22
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.0lYoud9tTN -
65156beb5c09c9bce586883eebb891f7739c6a22984fa2d464859907eebf9f86
Embedded URLs
- https://gettraff.ru/wb?keyword=the%20politics%20of%20power%207th%20edition
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/metor.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/09b03b.pdf
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/xubub-fojuwef-poliga-jutavitafoj.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/d1ee3c84.pdf
- https://wuwuleli.weebly.com/uploads/1/3/1/3/131398564/dubisilameso.pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f8735bb6f6d0.pdf
- https://cdn-cms.f-static.net/uploads/4376870/normal_5f8b7fb560d23.pdf
- https://uploads.strikinglycdn.com/files/9853102e-1b02-4504-a6ee-67f4f321e041/10475744027.pdf
- https://uploads.strikinglycdn.com/files/d749225a-0200-4166-8173-2b16cd16cda6/bipodobafalerisu.pdf
- https://cdn-cms.f-static.net/uploads/4366004/normal_5f87000306159.pdf
- https://cdn-cms.f-static.net/uploads/4378153/normal_5f8ba060ec52a.pdf
- https://cdn-cms.f-static.net/uploads/4366659/normal_5f875a8fd63e1.pdf
- https://cdn-cms.f-static.net/uploads/4366639/normal_5f89a019eb24c.pdf
- https://cdn-cms.f-static.net/uploads/4368223/normal_5f8910838d569.pdf
- https://cdn-cms.f-static.net/uploads/4370530/normal_5f893c26db31e.pdf
- https://cdn-cms.f-static.net/uploads/4370097/normal_5f8881245eb00.pdf
- https://cdn-cms.f-static.net/uploads/4379722/normal_5f8c0583e941d.pdf
- https://cdn-cms.f-static.net/uploads/4374535/normal_5f8922bbc57d2.pdf
- https://cdn-cms.f-static.net/uploads/4365560/normal_5f896a6276b6a.pdf
- https://dofazodasi.weebly.com/uploads/1/3/0/8/130873943/3333284.pdf
- https://zuwumepegowivos.weebly.com/uploads/1/3/1/0/131069935/360332.pdf
- https://fuvipizewovotat.weebly.com/uploads/1/3/1/0/131069886/dbc81c1913b5ae.pdf
- https://nudopimiga.weebly.com/uploads/1/3/1/0/131070212/8339731.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- zoxuzuxebexot.weebly.com
- jatorogerujew.weebly.com
- viweposedijul.weebly.com
- jawasolasazilem.weebly.com
- wuwuleli.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- dofazodasi.weebly.com
- zuwumepegowivos.weebly.com
- fuvipizewovotat.weebly.com
- nudopimiga.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 74.178.76.128
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report