MALICIOUS — 91688037471.pdf
MALICIOUS — 91688037471.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
812f5a4d1a32692e5a262b731fd3520ad990093ccf3935add1604897b7e0d25d - SHA-1:
a6c1ab585fc76c30d5d6e91e823b13f2d506a9e8 - MD5:
b2c4a9dde7423cd73c22a70a378a5702 - ssdeep:
1536:q2PdfWAia632LAWm7g/9NdGsi79LUb2qSi7rSSwKikRU10KkiW6pOu29TPSeWld4:fPdfmP32CE/7jDbowrSSmkPu29Gb3rb+ - TLSH:
T14739D1F71187ED5CB69B9F436EBA115DB14BD3986022AB441048B71CC5BC5BE7F20A20 - Submitted as: 91688037471.pdf
- File type: pdf · Size: 86343 bytes
- Verdict: malicious (98/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Embedded link rated suspicious by URL analysis: http://cdkkck.com/uploadfile/file/20210628045205.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://purebodycare.courses/wp-content/plugins/super-forms/uploads/php/files/4k1mi48593b8shd4eijdjs5f8h/vibodotuvik.pdf, https://eandjfamilyhealthcenter.com/wp-content/plugins/super-forms/uploads/php/files/a9e23389becbc818a0c2da8f1daf77ef/43526120155.pdf, http://vakantie-noordlimburg.nl/ckfinder/userfiles/files/dumisukubaz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 3 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1024 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 250.255.255.239.in-addr.arpa
- ff02::1:3
- 224.0.0.252
- 224.0.0.251
- ff02::fb
- 169.254.255.255
- 10.240.0.255
- 10.240.0.1
- ff02::16
- 224.0.0.22
- ff02::1:ff12:3456
- ff02::1:2
- 255.255.255.255
- ff02::1
- 135.232.92.137 US · Boydton · AS8075 Microsoft Limited
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.d7CzNAmkbN -
5de3fc31cb4c207d0755d0b65f36cb313682611db4782f4aeb982d8c7812c3e3
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/6naE_Nh8_CY/uplcv?utm_term=musafir+bangla+movie+song+mp3+download
- https://purebodycare.courses/wp-content/plugins/super-forms/uploads/php/files/4k1mi48593b8shd4eijdjs5f8h/vibodotuvik.pdf
- https://eandjfamilyhealthcenter.com/wp-content/plugins/super-forms/uploads/php/files/a9e23389becbc818a0c2da8f1daf77ef/43526120155.pdf
- http://vakantie-noordlimburg.nl/ckfinder/userfiles/files/dumisukubaz.pdf
- http://naturalmis.com/userfiles/file/69882892720.pdf
- https://bizdrive.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1/1608310ee8f850---tilutabaluxuxajub.pdf
- https://www.chauffeur-prive-nice.fr/wp-content/plugins/formcraft/file-upload/server/content/files/16082298db79e3---32795006545.pdf
- http://prograsifkalip.com/files/tasadevokuko.pdf
- http://cdkkck.com/uploadfile/file/20210628045205.pdf
- http://0851gay.org/userfiles/202106file/2021061807103870554.pdf
- https://beautifullifeuk.com/wp-content/plugins/super-forms/uploads/php/files/641aeefb8455e5d8c5e1bc3c15ab96ba/3260188172.pdf
- https://functionalmovement.gr/wp-content/plugins/super-forms/uploads/php/files/cc7d38da8e71634bfaeb601fbbb2a9d7/48683403059.pdf
- http://atenngo.com/admin/sites/site/documents/jedutenifepom.pdf
- http://e1pl2.nazwa.pl/busy/fotki/file/19768228388.pdf
- http://residenzaeden-albisola.com/userfiles/files/66152688932.pdf
- http://www.adatechotomasyon.net/wp-content/plugins/formcraft/file-upload/server/content/files/1607447778aa71---39421538908.pdf
- https://viajespereira.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a82073bbccd---33760400934.pdf
- https://stewsites.com/wp-content/plugins/super-forms/uploads/php/files/41e7339ef413383e3b35d865e941212c/jitetinexam.pdf
- https://adbadog.com/wp-content/plugins/super-forms/uploads/php/files/cdab5a92a74c915c118b414da7f75149/jijadiwikisudo.pdf
- https://bohemiamaestro.com/webpagebuilder/ckfinder/userfiles/files/450656308.pdf
- https://fjordancv.info/wp-content/plugins/super-forms/uploads/php/files/a348bc928c5f5060a1af33bf385f509a/67611699301.pdf
- http://inwallendorf.de/userfiles/file/39095766704.pdf
- https://ahi.com.ua/wp-content/plugins/super-forms/uploads/php/files/a34face3f7c32e5bdf2731fa42391f60/jutusurumajifaga.pdf
- https://www.disbel.es/ckfinder/userfiles/files/vazaverizulire.pdf
- https://anthonygillant.com/userfiles/file/31949785061.pdf
Embedded domains
- feedproxy.google.com
- eandjfamilyhealthcenter.com
- vakantie-noordlimburg.nl
- naturalmis.com
- bizdrive.nl
- www.chauffeur-prive-nice.fr
- prograsifkalip.com
- cdkkck.com
- 0851gay.org
- beautifullifeuk.com
- atenngo.com
- e1pl2.nazwa.pl
- residenzaeden-albisola.com
- www.adatechotomasyon.net
- viajespereira.com
- stewsites.com
- adbadog.com
- bohemiamaestro.com
- fjordancv.info
- inwallendorf.de
- ahi.com.ua
- www.disbel.es
- anthonygillant.com
- www.w3.org
- purl.org
Embedded IP addresses
- 135.232.92.137
- 40.79.141.152
- 104.21.85.170
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report