MALICIOUS — 59910748328.pdf
MALICIOUS — 59910748328.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a45cdf1b013a6c3e77f7353fcae7dfb54677042cb1eea07b6bdc8ac41883f0ed - SHA-1:
3d1ce87fa2a1e5cb5956be9520ab8972cb1f6f29 - MD5:
d20cadab6da4efaf4f42a46d4392062b - ssdeep:
1536:rqv2+CggwQQaubH2zirTwNZDC4gBDSz/GWkNpOP39PRWlaBSxlHgOX+iNS:cMwz0ifSC4FrPNPobl+d - TLSH:
T10F38CFF321E3DC4C779BDB872AE7127C649AD2486172EA948088FB6CC4AC0BE7D54550 - Submitted as: 59910748328.pdf
- File type: pdf · Size: 77659 bytes
- Verdict: malicious (98/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Embedded network infrastructure: http://elijasprojekts.lv/files/file/50494718440.pdf, http://lakesnwoodskerala.com/uploads/file/liniwipex.pdf, http://dental-forum.ru/userfiles/file/58959732850.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 4 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1124 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- desktop-hsgcbep
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- geover.prod.do.dsp.mp.microsoft.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ff02::1:3
- 224.0.0.252
- 224.0.0.251
- ff02::fb
- 10.240.0.1
- 10.240.0.255
- 169.254.255.255
- ff02::1
- 239.255.255.250
- ff02::1:ff12:3456
- 185.125.190.58
- 91.189.91.157
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.vvbuioC2zv -
4d4419c005e814edc0c47b517d48d689d47ff1c9182afdda37eabf51bc4ee559
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/1KS0DP0cxss/uplcv?utm_term=arcane+tracker+android
- http://elijasprojekts.lv/files/file/50494718440.pdf
- http://lakesnwoodskerala.com/uploads/file/liniwipex.pdf
- http://dental-forum.ru/userfiles/file/58959732850.pdf
- http://maxitelt.no/wp-content/plugins/formcraft/file-upload/server/content/files/16139d12cf3750---bemulasanuk.pdf
- http://artmetinc.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613d36e66d0f5---59830146826.pdf
- http://les-dvorik.ru/userfiles/file/71972971065.pdf
- https://bdblue.com/ckfinder/userfiles/files/menejivi.pdf
- http://fese.in/ienupdimages/images/files/48578025635.pdf
- https://gmt-tw.com/app/webroot/userfiles/files/fesixopukowixi.pdf
- http://ceramkgres.ru/userfiles/file/pigasekoduzoziligisati.pdf
- https://iamluno.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132cf256b636---94498977058.pdf
- https://nazrabilisim.com/calisma2/files/uploads/32331550626.pdf
- http://domki-kopalino.pl/pliki/36483035462.pdf
- https://certifiedmoversinc.com/wp-content/plugins/super-forms/uploads/php/files/4f843cd2cccdaad412e7b595334ca105/nugupuluvow.pdf
- http://stkvn.ru/wp-content/plugins/super-forms/uploads/php/files/ff0d750f308f057b098ed463908217cf/tibamekufafu.pdf
- http://kunbot.com/upload/files/benapeg.pdf
- https://thuanxuongmonmb.com/admin/webroot/upload/image/files/36658609241.pdf
- http://104.156.58.56/~web2inbox/wp-content/plugins/formcraft/file-upload/server/content/files/1613b473dd7ff3---84151137970.pdf
- http://poultech.net/d/files/39382107924.pdf
- http://wsmr.us/userfiles/file/pezewu.pdf
- http://alhouti.com/userfiles/file/putox.pdf
- http://www.sun-green.eu/ckfinder/userfiles/files/99503088806.pdf
- https://fullprotec.com/ckfinder/userfiles/files/raloxetevebiwexexiv.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- lakesnwoodskerala.com
- dental-forum.ru
- maxitelt.no
- artmetinc.com
- les-dvorik.ru
- bdblue.com
- fese.in
- gmt-tw.com
- ceramkgres.ru
- iamluno.com
- nazrabilisim.com
- domki-kopalino.pl
- certifiedmoversinc.com
- stkvn.ru
- kunbot.com
- thuanxuongmonmb.com
- poultech.net
- wsmr.us
- alhouti.com
- www.sun-green.eu
- fullprotec.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 104.156.58.56
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report