MALICIOUS — 9425fc91e2ac61bd2e12710cc86f72e985d8155aab48383e1a36418a30dc0218
MALICIOUS — 9425fc91e2ac61bd2e12710cc86f72e985d8155aab48383e1a36418a30dc0218 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9425fc91e2ac61bd2e12710cc86f72e985d8155aab48383e1a36418a30dc0218 - SHA-1:
503b1991f1cbb8741e1defbbb73d8d520797c478 - MD5:
6573217f02f0d11e55d3c99dd2cad4ed - ssdeep:
1536:6+tgBVmk5GZrLZ2o0Z51zcZkeA1vdVW6pOu2HZcVvo1WK4h75FaziTUm:3c7GFLZg/1zcZkeA1Au25cZoINwid - TLSH:
T13737BFF33197DD4CBB5B5B03B9BA01A8B089D78C6661DB500589B7BCD43C5BD7A20A20 - Submitted as: 9425fc91e2ac61bd2e12710cc86f72e985d8155aab48383e1a36418a30dc0218
- File type: pdf · Size: 74116 bytes
- Verdict: malicious (99/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://law.myvzl.com/wp-content/plugins/super-forms/uploads/php/files/81d5rp85vbh5gaojepij7g8112/38456927185.pdf, https://siam-royal-view.ru/data/files/badivizijinalisibewaverav.pdf, http://lgassociates.in/uploads/25644879943.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 3 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1068 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- desktop-hsgcbep
- ff02::1:3
- 224.0.0.252
- ff02::fb
- 224.0.0.251
- 10.240.0.1
- 169.254.255.255
- 10.240.0.255
- ff02::1:ff12:3456
- ff02::16
- ff02::2
- ff02::1
- ff02::1:ff4c:1d1d
- 224.0.0.22
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.kqeXsyKy2v -
98c410ba25ee7f50e0ecfc296406df6230e326472497f129837634fdadaa6523
Embedded URLs
- https://feedproxy.google.com/~r/Gsjc/~3/1hHberoKktI/uplcv?utm_term=the+iconic+hagia+sophia+grand+mosque+is+located+in+which+country
- https://law.myvzl.com/wp-content/plugins/super-forms/uploads/php/files/81d5rp85vbh5gaojepij7g8112/38456927185.pdf
- https://siam-royal-view.ru/data/files/badivizijinalisibewaverav.pdf
- http://lgassociates.in/uploads/25644879943.pdf
- https://www.retake.dk/ckfinder/userfiles/files/suwus.pdf
- https://slezanie.eu/userfiles/file/25119144181.pdf
- http://haliburtonhighlandsheritage.ca/userfiles/file/kovaxof.pdf
- https://master.plus/wp-content/plugins/super-forms/uploads/php/files/0c7dfff2e64940d1ea9e33bb083621c3/88326124500.pdf
- https://kurishupally.org/userfiles/file/rebotiziruzeta.pdf
- http://dolonchem.com/upload/files/mosuwozolumutuganulog.pdf
- https://funbugs.ie/userfiles/file/sawuxulepatava.pdf
- https://amezdigital.com/wp-content/plugins/super-forms/uploads/php/files/0d12abdb2061440b88068660c26ca6f5/kexenirumawumid.pdf
- https://alley.52886.tw/uploads/files/36178304587.pdf
- http://thehbbq.com/uploads/files/nufodokuxozerikokigir.pdf
- http://namuvaldymas.lt/userfiles/file/mizaka.pdf
- http://www.musicmaestrodiscos.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1613beecae7242---35614815551.pdf
- http://www.motionmantra.com/userfiles/files/26953434108.pdf
- https://asoriofrio.org/ckfinder/userfiles/files/joxis.pdf
- http://giaydantuongphongngudep.com/images/news/file/betenubog.pdf
- https://eurotig.ro/file/63499271553.pdf
- http://theheavent.com/userfiles/files/42196664163.pdf
- https://etadelloro.it/images/file/wisusafebaviboboza.pdf
- http://tetobox-budapest.hu/uploads/files/mabatogezetadidax.pdf
- http://polimak.pl/userfiles/file/ravisilamexoluwawa.pdf
- http://cokhihoangvinh.com/uploads/userfiles/file/davitapilufoji.pdf
Embedded domains
- feedproxy.google.com
- law.myvzl.com
- siam-royal-view.ru
- lgassociates.in
- slezanie.eu
- haliburtonhighlandsheritage.ca
- kurishupally.org
- dolonchem.com
- amezdigital.com
- alley.52886.tw
- thehbbq.com
- www.musicmaestrodiscos.co.uk
- www.motionmantra.com
- asoriofrio.org
- giaydantuongphongngudep.com
- theheavent.com
- etadelloro.it
- polimak.pl
- cokhihoangvinh.com
- www.w3.org
- purl.org
- ns.adobe.com
- www.retake.dk
- master.plus
- funbugs.ie
Embedded IP addresses
- 51.132.193.104
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report