MALICIOUS — 54735615327.pdf
MALICIOUS — 54735615327.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
788f09322e119caf07d575c0fe03048777e444ecf3ab62f09efde020d19dae2b - SHA-1:
e7a633245ab364e7c6ca24fe08295d9fcf865b27 - MD5:
6ae502be908493d6c2137fdfebcdf10f - ssdeep:
1536:Kc7hAyUWK2lwwAN/h2TTgf2JX+SDubRr9Of+pNEjLW8pO+gWKfpL3G0Fd3:lhAytK2lw72s8+Ie19OWpaS+uL3lv - TLSH:
T1703AD1F32197ED8CBA57AF0391EB219C614AE7882176E7905098B72CC4BCBBD3B14151 - Submitted as: 54735615327.pdf
- File type: pdf · Size: 96947 bytes
- Verdict: malicious (98/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Embedded link rated suspicious by URL analysis: http://sieuthicayxanh.vn/webroot/img/files/mapejurazisapekurefebite.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://northstarexecutivesearch.com/wp-content/plugins/super-forms/uploads/php/files/57612224c3d8ea98f8d65a7eb7d32fd5/82261151412.pdf, http://mgmkt.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160c94183b1cc9---33874139165.pdf, http://webinaris.training/ckfinder/userfiles/publics/files/vekovapog.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
1122 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- none
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.9OVLjGehkn -
1b3c6f52ec4713456af53b77abc23f389d77298b5cb4cc0a998ad09dbabc98cb
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/DOqCt-cVA4I/uplcv?utm_term=call+of+duty+mobile+offline+mod
- https://northstarexecutivesearch.com/wp-content/plugins/super-forms/uploads/php/files/57612224c3d8ea98f8d65a7eb7d32fd5/82261151412.pdf
- http://mgmkt.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160c94183b1cc9---33874139165.pdf
- http://webinaris.training/ckfinder/userfiles/publics/files/vekovapog.pdf
- https://ingatlansos.hu/images/userfiles/file/94252980779.pdf
- https://socialacademy.gr/wp-content/plugins/super-forms/uploads/php/files/30da9b0167f5a879ffa0920b157110ea/xuvela.pdf
- http://sieuthicayxanh.vn/webroot/img/files/mapejurazisapekurefebite.pdf
- http://www.tif.cn/wp-content/plugins/super-forms/uploads/php/files/126uh4ml129euo7uhgsitjjj8v/86635499747.pdf
- http://jncs.kr/page_data/file/20210728011712.pdf
- http://canxetaidientu.com/images/file/xidofitoz.pdf
- http://auroraenergyproject.it/userfiles/files/sijiborobuvar.pdf
- https://area34.info/wp-content/plugins/super-forms/uploads/php/files/dg9mi8pn0kapl69665tavhj9p2/rejixajubatoga.pdf
- https://teplitsyoptom.ru/wp-content/plugins/super-forms/uploads/php/files/fb93bb5a0a612b412b995ae03c6958ab/94207921618.pdf
- https://ecoinkworld.com/wp-content/plugins/super-forms/uploads/php/files/cfd209f634a765d486b24be5b596e1e9/perirakulitadoj.pdf
- http://48bulls.com/js/upload/files/88782499322.pdf
- https://yourtuscanyguide.com/wp-content/plugins/super-forms/uploads/php/files/gt235jo0kos03d5a5idu38mq62/52718156871.pdf
- http://amwordpress.org/wp-content/plugins/formcraft/file-upload/server/content/files/160a43bfa8a0a9---11683430845.pdf
- https://congnghieptauthuyvietnam.vn/upload/files/36007568901.pdf
- http://alsumiri.net/wp-content/plugins/super-forms/uploads/php/files/9891f3f34cf46f01de05a26a4d12c203/67061789307.pdf
- https://alariel.be/userfiles/file/kafimeputulabubebafukodi.pdf
- http://nuitsdartistes.eu/images/file/juxagutegudid.pdf
- http://greathorserider.com/ckfinder/userfiles/files/21349852290.pdf
- https://polinagerz.ru/wp-content/plugins/super-forms/uploads/php/files/1o85gp38n7b8i8b15e7ri00qrb/kafovurivolajurexikaluj.pdf
- https://www.simplythebestevents.ca/wp-content/plugins/formcraft/file-upload/server/content/files/160987522e4e66---44274391039.pdf
- https://beysukonaklari.com/ckfinder/userfiles/files/20937676489.pdf
Embedded domains
- feedproxy.google.com
- northstarexecutivesearch.com
- mgmkt.com.br
- www.tif.cn
- jncs.kr
- canxetaidientu.com
- auroraenergyproject.it
- area34.info
- teplitsyoptom.ru
- ecoinkworld.com
- 48bulls.com
- yourtuscanyguide.com
- amwordpress.org
- alsumiri.net
- alariel.be
- nuitsdartistes.eu
- greathorserider.com
- polinagerz.ru
- www.simplythebestevents.ca
- beysukonaklari.com
- hafa-verein.de
- gordostcrista.ru
- merrygoldholidays.com
- q8.ai
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report