MALICIOUS — marofukiwipu.pdf
MALICIOUS — marofukiwipu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
7235f2085548aafdbfff2700f7c22bc784aa31ae8c83b0915bf71bb280789caf - SHA-1:
e6c3f78db587abd828b44d3187af4d088939ae7f - MD5:
bbc2f3aae219805d375f231c5166b700 - ssdeep:
1536:GC+pPBagAovMCnurnY6ykbxf4bU89RB7WWOpOwrKWFFNUwY8rejKBVzyrfi:t+sFnYabxf4I89RRLwrFPVrsi - TLSH:
T13739C0F37187CE4C76AB9F436AAB127CA04AE3586562DF900088766DC9BC97DBE04501 - Submitted as: marofukiwipu.pdf
- File type: pdf · Size: 88767 bytes
- Verdict: malicious (99/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 30 external host(s) at runtime (7 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://smidgel.ru/uplcv?utm_term=beware+the+dog+roald+dahl+pdf, https://singaporeroadshow.com/wp-content/plugins/super-forms/uploads/php/files/8d650e330b03328360ed8d9884405c89/rudowejowuvuje.pdf, http://jjmcp.jp/userfiles/Image/file/96870866224.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9826 behavior events · 1 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/2cbcf400-ac8d-4d86-9d69-c7f0dff56d2e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/2cbcf400-ac8d-4d86-9d69-c7f0dff56d2e?P1=1787114262&P2=404&P3=2&P4=GbzT2J5mZkwsyhMG4Qh965Zy4seitGVLf2Srd%2bGmXJd3uVVJfSZTIW4Bl40z7%2bHh1s1HRjgvcX%2fWrbBvL21ZSQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/58b2a9b1-8570-476c-a7c2-f7ab0a20fbf9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/31325/files/a52e00352b052d85e4734b2b8b132c99f2559cf9df647f1903a57bc1fed3f95c -
a52e00352b052d85e4734b2b8b132c99f2559cf9df647f1903a57bc1fed3f95c - /opt/CAPEv2/storage/analyses/31325/files/9fb4ba6724c7de4cdabf31bfc7f389c9377e80cb44c0ab24e988da3dd26c4d29 -
9fb4ba6724c7de4cdabf31bfc7f389c9377e80cb44c0ab24e988da3dd26c4d29 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.4WIJqWD0gB -
1ff2aa686a916033c7e51916a7a909c6b13574bdcd9f8bf510901b5b3f1ff7c5
Embedded URLs
- https://smidgel.ru/uplcv?utm_term=beware+the+dog+roald+dahl+pdf
- https://singaporeroadshow.com/wp-content/plugins/super-forms/uploads/php/files/8d650e330b03328360ed8d9884405c89/rudowejowuvuje.pdf
- http://jjmcp.jp/userfiles/Image/file/96870866224.pdf
- http://tasteofruraleurope.eu/upload/File/rasonitutowi.pdf
- http://videoacceso.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609481f21e43c---junojas.pdf
- https://www.wemservice.com/ckfinder/userfiles/files/13375451993.pdf
- https://expresstestingatl.com/wp-content/plugins/super-forms/uploads/php/files/62798cc10e3e44388e0456b063c9aa86/13123109860.pdf
- https://www.hauptsache.cc/wp-content/plugins/formcraft/file-upload/server/content/files/16118949a45883---wirutusiwitinikamipifa.pdf
- http://oilandgaswork.com/userfiles/file/sereja.pdf
- https://damiel.eu/userfiles/file/komotuxuwiwi.pdf
- https://limadelimon.com/images/file/rofesurutiserixizex.pdf
- https://masini-de-ambalat.ro/images/userfiles/nafax.pdf
- http://greddy.com/admin/common/ckfinder/userfiles/File/wamotesakibitopilusebuwo.pdf
- http://rotarytattoomachine.co/project-new/christianbook/upload_images/file/18322707485.pdf
- https://www.histoiresdegroupes.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607a930f884a4---ligebifiz.pdf
- https://www.ltgpartners.com/wp-content/plugins/super-forms/uploads/php/files/d112c716d7b01f23371c7b82df3bbe66/gasupopunixokek.pdf
- https://promocionesnma.com/wp-content/plugins/super-forms/uploads/php/files/2324d4d6b97ec09e309d92e2849136fa/3012890920.pdf
- https://miamivanservice.net/wp-content/plugins/formcraft/file-upload/server/content/files/160890251353e2---49401584840.pdf
- https://storage-in-motion.com/wp-content/plugins/formcraft/file-upload/server/content/files/160856e5fb6544---3446224979.pdf
- https://medius.sk/userfiles/file/nutifibedikafobilajujopix.pdf
- https://www.lightingdynamics.com/wp-content/plugins/super-forms/uploads/php/files/5460da679b521d0e066f907a8b6e3ea7/72455069115.pdf
- http://vom-ragnaroek.de/uploads/file/95537731447.pdf
- http://www.shipsupply.co.mz/wp-content/plugins/formcraft/file-upload/server/content/files/16087a686b2e5d---suxuginofobipepuwiro.pdf
- https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/1993410fa29d74da6fa5b737c6986ab9/53334920156.pdf
- http://geology.ie/wp-content/plugins/formcraft/file-upload/server/content/files/1606fb82d45830---xijemi.pdf
Embedded domains
- smidgel.ru
- singaporeroadshow.com
- jjmcp.jp
- tasteofruraleurope.eu
- videoacceso.com
- www.wemservice.com
- expresstestingatl.com
- www.hauptsache.cc
- oilandgaswork.com
- damiel.eu
- limadelimon.com
- greddy.com
- rotarytattoomachine.co
- www.histoiresdegroupes.com
- www.ltgpartners.com
- promocionesnma.com
- miamivanservice.net
- storage-in-motion.com
- www.lightingdynamics.com
- vom-ragnaroek.de
- alenakovalchuk.ru
- avenirpourtous.fr
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 20.42.65.94
- 52.123.252.244
- 4.230.171.124
- 85.210.193.152
- 20.247.184.197
- 20.165.94.54
- 74.178.76.128
- 52.123.129.14
- 40.99.134.18
- 51.105.71.136
- 203.26.79.13
- 74.178.232.29
- 20.165.94.63
- 20.42.73.31
- 172.175.111.170
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report