MALICIOUS — givudufigumudupedemu.pdf
MALICIOUS — givudufigumudupedemu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100). 4 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
26a848467f407312db061fe53f3756476fa6979cdb6d1ae6fd97e30d1fb60e5d - SHA-1:
0f09c5ef382547d04412139996ee7c96ca62cd51 - MD5:
17f8da1c2a2c48d7c6de61c3b9c1593e - ssdeep:
1536:b/e7qyLMhuzdFOVgyXaMx7t9BfHL6z0x8ATF3psGsjWIh4c5RAWspORLTX:vFhZNaugzK8YC5HRbR/ - TLSH:
T19438CFF332A7DE8C7B8A5F132A6E0158618ED78C7552ABA04189B23CD47C5FEAF10550 - Submitted as: givudufigumudupedemu.pdf
- File type: pdf · Size: 77225 bytes
- Verdict: malicious (100/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded link rated suspicious by URL analysis: http://www.agrosystem.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/16142b2ab9e984---veziseruzojigevizosegawid.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://queure.ru/uplcv?utm_term=how+to+check+gpu+in+android, http://caphegiabao.com/upload/fck/file/83080733199.pdf, http://www.agrosystem.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/16142b2ab9e984---veziseruzojigevizosegawid.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 6 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
974 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- ntp.ubuntu.com
- desktop-hsgcbep
- 10.240.0.1
- 138.201.132.148 DE · Falkenstein · AS24940 Hetzner Online GmbH
- 255.255.255.255
- 185.125.190.58
- ff02::16
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- ff02::2
- ff02::1:ff4c:1d1d
- ff02::1
- ff02::1:ff12:3456
- 149.154.167.99 NL · Amsterdam · AS62041 Telegram Messenger Network
- 224.0.0.22
- ff02::1:2
- 185.125.190.57
- 74.178.76.128 IE · Dublin · AS8075 Microsoft Corporation
- 20.165.94.46 US · San Antonio · AS8075 Microsoft Corporation
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.jdgsPDqxl8 -
1fd93dbf2de1740211ce45a654664e4e821e4a80a588d1acaf7bd766fa401628
Embedded URLs
- https://queure.ru/uplcv?utm_term=how+to+check+gpu+in+android
- http://caphegiabao.com/upload/fck/file/83080733199.pdf
- http://www.agrosystem.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/16142b2ab9e984---veziseruzojigevizosegawid.pdf
- http://le-lemniscus-incandescent.fr/ckeditor/upload/files/tolelunopevatu.pdf
- http://dotacjedlaoze.pl/userfiles/file/7159509566.pdf
- https://vaitinhdien.com/app/webroot/upload/files/sisili.pdf
- https://mdteam.se/ckfinder/userfiles/files/fakixo.pdf
- http://abwmechanicsville.com/uploads/files/51720477231.pdf
- http://slovoveri.org/userfiles/39403034664.pdf
- https://producedepot.us/userfiles/files/94827702814.pdf
- http://togclick.com/media/userFckfiles/file/wapemuvafotojuziwisu.pdf
- http://candleelectricals.com/uploaded_files/userfiles/files/55466483513.pdf
- http://kk-gorenjska.si/uporabnik/file/potitabesededaxebuw.pdf
- http://tiendanatacion.com/noticias/files/77073953882.pdf
- http://castrolmintabolt.hu/images/upload/file/87032932293.pdf
- http://nikolalepojevic5.com/multimedia/file/97223664755.pdf
- http://uekekb.ru/!upload/files/xamuwapixekon.pdf
- http://sperrincaravans.com/images/file/18142548887.pdf
- http://capableapp.com/uploads/files/14710027887.pdf
- http://schroniskoorzechowce.pl/ckfinder/userfiles/files/4653782648.pdf
- http://vekosgroup.ru/userfiles/file/koxikadinozuvapujaloze.pdf
- http://hyunbulsa.org/~ewedd2/userfiles/file/rotixigasefirepopap.pdf
- http://lichnyiybrand.ru/wp-content/plugins/formcraft/file-upload/server/content/files/16135f73f6ebc0---55245092018.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- queure.ru
- caphegiabao.com
- le-lemniscus-incandescent.fr
- dotacjedlaoze.pl
- vaitinhdien.com
- mdteam.se
- abwmechanicsville.com
- slovoveri.org
- producedepot.us
- togclick.com
- candleelectricals.com
- tiendanatacion.com
- nikolalepojevic5.com
- uekekb.ru
- sperrincaravans.com
- capableapp.com
- schroniskoorzechowce.pl
- vekosgroup.ru
- hyunbulsa.org
- lichnyiybrand.ru
- www.w3.org
- purl.org
- ns.adobe.com
- www.agrosystem.com.tr
- kk-gorenjska.si
Embedded IP addresses
- 138.201.132.148
- 149.154.167.99
- 74.178.76.128
- 20.165.94.46
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report