MALICIOUS — wolixifope.pdf
MALICIOUS — wolixifope.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
85ac2d646d60229a162e9a7e1347e5422b4aee3c59ccd4454b674499448ddfaf - SHA-1:
a81adaa46811233a37906fd66f6834c1f77b2593 - MD5:
95d9508e73b7493136b14de94c96a3e8 - ssdeep:
1536:kotc06awWC8puPEY5YGgO/Mg1mYm+Bfx1wpFhhRZjWELpoRmMUWspO2+W8DDEXV4:NcG4b5YPOUgy+Bfx1wVlymMX2KDDh - TLSH:
T17539C1F32297DD0C76C6AF47A5AA01AC704AD7842131EA9141C8B66CD4BCAFDFF14612 - Submitted as: wolixifope.pdf
- File type: pdf · Size: 90535 bytes
- Verdict: malicious (98/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Embedded network infrastructure: https://www.cr-sdc.org/wp-content/plugins/super-forms/uploads/php/files/950c340a834e7291657dedddc243576c/nomibilixopubewid.pdf, https://centar-znr-zop.hr/wp-content/plugins/formcraft/file-upload/server/content/files/160b2f8fa226e6---63615164324.pdf, http://ozgu-yapi.com/firma/files/sazedibelezoritijej.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 7 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1010 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep
- ntp.ubuntu.com
- ff02::1:3
- 224.0.0.252
- 224.0.0.251
- ff02::fb
- 10.240.0.255
- 10.240.0.1
- ff02::16
- 169.254.255.255
- 224.0.0.22
- 185.125.190.57
- 91.189.91.157
- 20.42.65.91 US · Flint Hill · AS8075 Microsoft Corporation
- 239.255.255.250
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.A2MWfexq7M -
5e0bf6c790072932dcd91d54c54d161ff4128b88af091cca74fb4e5f8ed9616e
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/S30rS-6n6vg/uplcv?utm_term=ibn+qayyim+books+in+urdu
- https://www.cr-sdc.org/wp-content/plugins/super-forms/uploads/php/files/950c340a834e7291657dedddc243576c/nomibilixopubewid.pdf
- https://centar-znr-zop.hr/wp-content/plugins/formcraft/file-upload/server/content/files/160b2f8fa226e6---63615164324.pdf
- http://ozgu-yapi.com/firma/files/sazedibelezoritijej.pdf
- http://fluidearthconcrete.com/userfiles/file/32704804092.pdf
- http://archinfo.ru/uploads/file/29612210644.pdf
- http://villaturri.com/wp-content/plugins/formcraft/file-upload/server/content/files/160e48af979e17---zawedolumuguniz.pdf
- https://ipssecurityconsultants.com/ckfinder/userfiles/files/56439177876.pdf
- http://www.nuricomuvakfi.org/wp-content/plugins/super-forms/uploads/php/files/q50p0r5lidpl5ri859f22q09u3/bamugeridunaluzo.pdf
- https://shrmivirtual.org/wp-content/plugins/super-forms/uploads/php/files/cbffaacb256c3a1df8188e286904ec28/kigudewesakigu.pdf
- http://allmedicus.com/userfiles/file/sozepukoxagawejopazobiz.pdf
- http://traditionsradio.com/wp-content/plugins/super-forms/uploads/php/files/0160bff9d34747544a6ac6e1a29598f6/jikukofilujoxam.pdf
- http://krzysztofmalec.pl/gfx/fck/file/35560898190.pdf
- https://bokseinstituttet.dk/wp-content/plugins/formcraft/file-upload/server/content/files/160be7ad62589f---54777703492.pdf
- https://loan-financial.com/wp-content/plugins/super-forms/uploads/php/files/a308b8d312c7ece72e89ac71373a0e34/jopumugaku.pdf
- http://hanart21.com/files/userfiles/file/62623534743.pdf
- https://noble-program.site/js/ckfinder/userfiles/files/zorepobesokule.pdf
- http://asdgolfclubtoscana.com/writable/public/userfiles/file/14445824023.pdf
- http://sofia-es.tokyo/yamituki-n/uploads/files/41356598296.pdf
- http://projectbudapest.hu/wp-content/plugins/formcraft/file-upload/server/content/files/16081c64e492b8---mibuteridixiwonigib.pdf
- https://luyenthitoeic.info/userfiles/file/48197618642.pdf
- http://gt-outillages.fr/ressource/site-image/files/gawobobe.pdf
- https://seataclighting.com/wp-content/plugins/super-forms/uploads/php/files/f2c751fa2c92cb903b5662a2c55348d0/60470751907.pdf
- https://adsbudget.net/userfiles/file/68781285443.pdf
- https://endoaccessories.com/wp-content/plugins/super-forms/uploads/php/files/1ib1e2ceqm9d6es8lkl9n2nvni/kalunew.pdf
Embedded domains
- feedproxy.google.com
- www.cr-sdc.org
- ozgu-yapi.com
- fluidearthconcrete.com
- archinfo.ru
- villaturri.com
- ipssecurityconsultants.com
- www.nuricomuvakfi.org
- shrmivirtual.org
- allmedicus.com
- traditionsradio.com
- krzysztofmalec.pl
- loan-financial.com
- hanart21.com
- noble-program.site
- asdgolfclubtoscana.com
- luyenthitoeic.info
- gt-outillages.fr
- seataclighting.com
- adsbudget.net
- endoaccessories.com
- www.w3.org
- purl.org
- ns.adobe.com
- centar-znr-zop.hr
Embedded IP addresses
- 20.42.65.91
- 40.84.85.40
- 72.145.35.113
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report