MALICIOUS — pixupoza.pdf
MALICIOUS — pixupoza.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 50 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
79793a187f06d3763b3a49c871964711d1711b039a04ce9978c260deb906fd4b - SHA-1:
ccc5942fff93d4b4751d1f8a46067742ac56c6bc - MD5:
47151c08934826cffcf93eb67aaeb268 - ssdeep:
1536:fBq5bcfxLMk4wPiKCnqCxMVBhMD7+DV/UWOpOwrKWrG9qjaaL7gAU:Jq5bcH4w61txMVBhHxwrRaq9n0 - TLSH:
T1F637C0F722E7DD4C7A4A5F137AAF2068904AD3C86572FD900188B65CD1BC6BEBB00951 - Submitted as: pixupoza.pdf
- File type: pdf · Size: 70183 bytes
- Verdict: malicious (99/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Embedded link rated malicious by URL analysis: https://giolog.biz/images/bulk_images/files/95634871316.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 34 external host(s) at runtime (7 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://inspiredindianfoundation.org/uploads/rusowiboziludede.pdf, http://intechsol.kz/wp-content/plugins/formcraft/file-upload/server/content/files/1614f0c3fdd22d---fudegefasawali.pdf, http://hanboo.cn/Uploads/file/2021090502035470554.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9746 behavior events · 1 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- /opt/CAPEv2/storage/analyses/29677/files/f1166dff1142e6a24362c6701eb1badf2359fb6a3d21275602f7cd2fbc50088a -
f1166dff1142e6a24362c6701eb1badf2359fb6a3d21275602f7cd2fbc50088a - /opt/CAPEv2/storage/analyses/29677/files/4750a5d588e03ad5361b287d498bd2e1c23e175363c2f179d7577a4d8dda6aa5 -
4750a5d588e03ad5361b287d498bd2e1c23e175363c2f179d7577a4d8dda6aa5 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.i7ROWeIWER -
ecb0649a78e40a728c58dabc66fcabb892f79936872af717685bd1e2b1dfafcc
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/DOqCt-cVA4I/uplcv?utm_term=keyboard+with+arrow+keys+android
- http://inspiredindianfoundation.org/uploads/rusowiboziludede.pdf
- http://intechsol.kz/wp-content/plugins/formcraft/file-upload/server/content/files/1614f0c3fdd22d---fudegefasawali.pdf
- http://hanboo.cn/Uploads/file/2021090502035470554.pdf
- https://giolog.biz/images/bulk_images/files/95634871316.pdf
- http://redigonda.it/userfiles/files/61429951293.pdf
- http://geometrarontani.it/userfiles/files/tujim.pdf
- http://alternativefitness.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1614cc3496fe23---xanixunopodo.pdf
- http://naturestuff.nl/siteimages/file/21708970406.pdf
- http://proallprint.com/userfiles/files/58548588671.pdf
- https://principesgs.com/userfiles/file/fotubotewida.pdf
- https://metroguards.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1614bfb4f738be---doxitanegujaxola.pdf
- https://hankilfood.com/userfiles/file/20210924070527.pdf
- http://letdentalab.com/img/files/fonepejomatuteg.pdf
- http://w3-japan.com/js/upload/files/11270125187.pdf
- http://adice-area.com/pictures/files/rukezirezidagewituk.pdf
- https://learningsolution.ca/userfiles/files/86268806726.pdf
- http://www.coverseg.com/uploads/ckfinder/files/97640755862.pdf
- https://2winit.com/Files/files/74808292905.pdf
- http://axi-hohenstein.de/userfiles/file/bipif.pdf
- https://larrialdiak.es/files/galeria/files/nuvujavekinofu.pdf
- https://kes-stv.ru/wp-content/plugins/super-forms/uploads/php/files/4171b696badc7962d4e2544e09016b9c/loxizov.pdf
- https://www.lamuccacompany.com/wp-content/plugins/super-forms/uploads/php/files/fcc048d8200cb6add4f1c02bfd37df96/71912078346.pdf
- http://mega-treid.com/userfiles/files/jutinopubatikobipareji.pdf
- https://laurallo.com/ckfinder/userfiles/files/64753279971.pdf
Embedded domains
- feedproxy.google.com
- inspiredindianfoundation.org
- hanboo.cn
- giolog.biz
- redigonda.it
- geometrarontani.it
- alternativefitness.com.au
- naturestuff.nl
- proallprint.com
- principesgs.com
- metroguards.com.au
- hankilfood.com
- letdentalab.com
- w3-japan.com
- adice-area.com
- learningsolution.ca
- www.coverseg.com
- 2winit.com
- axi-hohenstein.de
- larrialdiak.es
- kes-stv.ru
- www.lamuccacompany.com
- mega-treid.com
- laurallo.com
- www.w3.org
Embedded IP addresses
- 52.123.252.216
- 52.110.12.26
- 52.110.12.3
- 4.230.171.124
- 40.84.85.40
- 52.230.59.222
- 52.253.84.76
- 135.233.95.144
- 135.233.95.135
- 40.99.134.18
- 20.42.65.84
- 52.123.128.14
- 135.233.95.80
- 203.26.79.13
- 4.150.223.97
- 142.250.195.238
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report