MALICIOUS — 94827702814.pdf
MALICIOUS — 94827702814.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ad53c056471b92dfaef5ce48638f13b403d479fbd0d3915e20b9c73b09b6b4d3 - SHA-1:
cc40be81b2e71f12006ecfc7adf0a25283514618 - MD5:
3990c5608054704366d2dd83dbff6ccc - ssdeep:
1536:yVy/k7zGEYPEVf0ohnapPA9d+QgYwslHWGpOKc4k+We3mD5t0Nki:qy/k72PEx3noP3QDuKc4kwez03 - TLSH:
T18339D0F35057EE4C774F4B4368E6119CA4C6DA893162EBA00588BB6DD0FCABEBE45140 - Submitted as: 94827702814.pdf
- File type: pdf · Size: 86838 bytes
- Verdict: malicious (98/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Embedded network infrastructure: http://jysfh.com/upload_fck/file/2021-9-6/20210906125225779664.pdf, http://metalzilembo.it/userfiles/files/vijajulubufitofamaj.pdf, https://thietbixanh.net/uploads/files/77468167367.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 9 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1009 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- 20.42.179.192 US · Moses Lake · AS8075 Microsoft Corporation
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- 10.240.0.1
- 224.0.0.251
- ff02::fb
- 224.0.0.22
- ff02::16
- ff02::2
- ff02::1:ff4c:1d1d
- ff02::1:ff12:3456
- 13.89.179.12 US · Des Moines · AS8075 Microsoft Corporation
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.25Trix2nc1 -
801ae46efb5ba68a60b6ca34dce4671a98df8d8a8073b7e330b53d2e950527d3
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/6naE_Nh8_CY/uplcv?utm_term=comic+android+app
- http://jysfh.com/upload_fck/file/2021-9-6/20210906125225779664.pdf
- http://metalzilembo.it/userfiles/files/vijajulubufitofamaj.pdf
- https://thietbixanh.net/uploads/files/77468167367.pdf
- http://khojedu.net/userfiles/file/bujivefusijilanesugo.pdf
- http://mayepnuocmia.vn/data/ckfinder/files/20773391076.pdf
- https://www.kiteschule-eckernfoerde.de/wp-content/plugins/formcraft/file-upload/server/content/files/16132c7df07144---21337573980.pdf
- https://glycocalyx.nl/userfiles/image/file/rupurememevanojivevupobow.pdf
- http://sapthagireesyathra.srikarpagavinayagamills.com/userfiles/file/kajurojopobolojude.pdf
- http://bluebirdcanada.com/FileData/ckfinder/files/20210923_4A36C49084135834.pdf
- https://sharidendesignasphalt.com/wp-content/plugins/super-forms/uploads/php/files/e895bf0da885e56cf7bde9422f6d3380/lijoz.pdf
- http://yuha.be/_files/file/fubelojaxiwunusawida.pdf
- http://allmedicus.com/userfiles/file/15517988794.pdf
- http://kccmaul.com/files/files/10404644440.pdf
- http://didula.com/img/file/22485501452.pdf
- https://sluganarodu.org/userfiles/files/xedegidipafijogaroda.pdf
- http://tydafa.com/dafa/uploadfiles/20210916233803.pdf
- http://www.moyekolodin.com/files/sininimekisel.pdf
- http://ageddfjtjgrade.pretty-match.com/upload/files/fivadovibekediwofiboxiriw.pdf
- https://agros.net/uploads/file/23515787547.pdf
- http://manu-transport.com/documents/file/gexizeti.pdf
- http://bubb.cn/up_file/file/bazowerilivixofepono.pdf
- http://tandartsindex.nl/images/uploads/12196395030.pdf
- http://szyuangang.com/UserFiles/file///putedudigojekopurojovog.pdf
- http://lapempi.nl/ckfinder/userfiles/files/29401914341.pdf
Embedded domains
- feedproxy.google.com
- jysfh.com
- metalzilembo.it
- thietbixanh.net
- khojedu.net
- www.kiteschule-eckernfoerde.de
- glycocalyx.nl
- sapthagireesyathra.srikarpagavinayagamills.com
- bluebirdcanada.com
- sharidendesignasphalt.com
- yuha.be
- allmedicus.com
- kccmaul.com
- didula.com
- sluganarodu.org
- tydafa.com
- www.moyekolodin.com
- ageddfjtjgrade.pretty-match.com
- agros.net
- manu-transport.com
- bubb.cn
- tandartsindex.nl
- szyuangang.com
- lapempi.nl
- www.w3.org
Embedded IP addresses
- 20.42.179.192
- 13.89.179.12
- 74.178.232.29
- 85.210.193.152
- 20.165.94.63
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report