MALICIOUS — luzivesumu.pdf
MALICIOUS — luzivesumu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100). 2 of 50 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
8683ca521e57e3fb61db35cbf65c5cd111e48e942c9612996d0e314707838293 - SHA-1:
da08e82d4ea838b0ef13b5ea33da05fcef5f8398 - MD5:
677ee6be2b7a1d077d19407c1e196dfa - ssdeep:
3072:aFIpPQAfoNRshJMRIBqspqNMsa3hnk7wDGLhpq0SV:qqPQAALsgNNM3hnW3s - TLSH:
T1B33AD0B30087EE4DB6CB5F439DA60198925ED74D612767B0088CAB2CA0FC7FD6E10561 - Submitted as: luzivesumu.pdf
- File type: pdf · Size: 100787 bytes
- Verdict: malicious (93/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 93/100 is the fusion of 8 weighted signals:
- Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Contacted 29 external host(s) at runtime (9 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/0f476ee6-1279-4a22-b94b-b74d562c514e/47110994501.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=soa%20design%20patterns%20pdf, https://uploads.strikinglycdn.com/files/0f476ee6-1279-4a22-b94b-b74d562c514e/47110994501.pdf, https://uploads.strikinglycdn.com/files/c6a0d181-2913-4624-bacf-6ab03ed1ba02/83588105745.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9904 behavior events · 1 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- c.pki.goog
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/2cbcf400-ac8d-4d86-9d69-c7f0dff56d2e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/2cbcf400-ac8d-4d86-9d69-c7f0dff56d2e?P1=1787096552&P2=404&P3=2&P4=HtuJokh%2flAC2Pn6PPT6pq0EPH%2fW16KPrYIugwEj1Fqlv9TA05TLwG8A56cqt%2b2JZuO038n4Fnm2tYCsW7FtixQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/58b2a9b1-8570-476c-a7c2-f7ab0a20fbf9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/58b2a9b1-8570-476c-a7c2-f7ab0a20fbf9?P1=1787096578&P2=404&P3=2&P4=f1qfvhILl%2bNOIe76E6UU1R%2fUdKqGlGLWhXOxfXI950a1NzvAvD5U%2fq48RUJjNZ9sInoHCcEeecyf6nLvbibFDw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://c.pki.goog/r/gsr1.crl
- http://c.pki.goog/r/r4.crl
Dropped files
- /opt/CAPEv2/storage/analyses/30867/files/e2b3c57f118c23ab7ac4b20db1871d17c8b30f19f2481aa92e3b18d656b10179 -
e2b3c57f118c23ab7ac4b20db1871d17c8b30f19f2481aa92e3b18d656b10179 - /opt/CAPEv2/storage/analyses/30867/files/145c0182e25fde3266c08daee40ab38b81e0e05dd6257117e04f32c9d18c22ad -
145c0182e25fde3266c08daee40ab38b81e0e05dd6257117e04f32c9d18c22ad - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.CD6JHSbHm9 -
477ddbe1a388703754396b56005eedd696ff16ce32274fabde13a6379a777b16
Embedded URLs
- https://ggtraff.ru/wb?keyword=soa%20design%20patterns%20pdf
- https://uploads.strikinglycdn.com/files/0f476ee6-1279-4a22-b94b-b74d562c514e/47110994501.pdf
- https://uploads.strikinglycdn.com/files/c6a0d181-2913-4624-bacf-6ab03ed1ba02/83588105745.pdf
- https://uploads.strikinglycdn.com/files/2f8f84f4-92e9-49e9-8915-e47e495942fa/dorawazokawepovut.pdf
- https://uploads.strikinglycdn.com/files/9949e29a-8894-4924-b052-1336d1d78016/fokutanitepanononowekora.pdf
- https://site-1040438.mozfiles.com/files/1040438/82963039158.pdf
- https://site-1037843.mozfiles.com/files/1037843/finoxupajasifap.pdf
- https://site-1038627.mozfiles.com/files/1038627/26561537355.pdf
- https://site-1043917.mozfiles.com/files/1043917/66036758620.pdf
- https://site-1039417.mozfiles.com/files/1039417/20332407141.pdf
- https://cdn-cms.f-static.net/uploads/4366011/normal_5f874bac9dd81.pdf
- https://cdn-cms.f-static.net/uploads/4369657/normal_5f882c1b42d14.pdf
- https://uploads.strikinglycdn.com/files/71896367-e63c-4733-b724-f19a7a14eafb/55668433741.pdf
- https://uploads.strikinglycdn.com/files/66ae4284-6232-46e8-8804-ce17a6799f73/271074013.pdf
- https://uploads.strikinglycdn.com/files/464c85d7-f815-416c-8113-fed838cea650/sibusadirevazidijunu.pdf
- https://cdn.shopify.com/s/files/1/0437/2715/9448/files/54683852839.pdf
- https://cdn.shopify.com/s/files/1/0492/9440/9884/files/2014_eic_worksheet.pdf
- https://cdn-cms.f-static.net/uploads/4369323/normal_5f8877f2a4144.pdf
- https://cdn-cms.f-static.net/uploads/4365541/normal_5f870be803431.pdf
- https://cdn-cms.f-static.net/uploads/4366339/normal_5f87316fa41f7.pdf
- https://cdn-cms.f-static.net/uploads/4366653/normal_5f871bef817d6.pdf
- https://cdn-cms.f-static.net/uploads/4368219/normal_5f8888468ddd0.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1040438.mozfiles.com
- site-1037843.mozfiles.com
- site-1038627.mozfiles.com
- site-1043917.mozfiles.com
- site-1039417.mozfiles.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 20.42.65.91
- 52.110.12.38
- 20.42.179.204
- 4.230.171.124
- 20.42.65.84
- 135.233.95.144
- 20.112.250.133
- 52.123.128.14
- 74.178.76.44
- 72.154.7.108
- 203.26.79.13
- 52.123.252.241
- 142.251.42.99
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report