MALICIOUS — xikalugolawel.pdf
MALICIOUS — xikalugolawel.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100). 3 of 23 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
b97fde96c5c06a6b34d3946dbec8ffa9de6f05d82a98f5169b8ccdaf25cc55ac - SHA-1:
b1997bb64be19e064d28628283926a83ac5f7ed5 - MD5:
f2e26adbd43df282782ac90cba82f9b4 - ssdeep:
1536:bwdQ+AaHF89j7Lmgja74nFqAomsZWW6pOu21ji8Wug/kVoaQN:8C+M9j2t7yFqAeTu2wTkVk - TLSH:
T14539D0F311E7CC9D7B855F039EEA1158B089D3882122EBA045C4766CD5AC9FE3F40A51 - Submitted as: xikalugolawel.pdf
- File type: pdf · Size: 88773 bytes
- Verdict: malicious (91/100)
Detections (3 of 23 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 91/100 is the fusion of 7 weighted signals:
- Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Contacted 28 external host(s) at runtime (3 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://preprodpcb.com/userfiles/files/10487412852.pdf, https://loan-financial.com/wp-content/plugins/super-forms/uploads/php/files/aba52a9df78cbc6d12dc3da7006edb32/25310268596.pdf, https://nnkcreations.com/userfiles/file/gozuxadowilosotanes.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9734 behavior events · 1 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- searchapp.bundleassets.example
- to-do.office.com
- staging.to-do.officeppe.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- desktop-hsgcbep
- ntp.ubuntu.com
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.85
- 23.11.37.157
- 20.190.142.164
Dropped files
- /opt/CAPEv2/storage/analyses/24768/files/dcc39054f9c3240b50e671fb941f92a433192c9f04b81dde0e2ef51b20455329 -
dcc39054f9c3240b50e671fb941f92a433192c9f04b81dde0e2ef51b20455329 - /opt/CAPEv2/storage/analyses/24768/files/7fad67c0881e31c6e45faf2971cdcdcef66b5f9f7ce604b8b9c4b7e5601e19ca -
7fad67c0881e31c6e45faf2971cdcdcef66b5f9f7ce604b8b9c4b7e5601e19ca - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.AJPxC0zePo -
5e619d2da1dd41fd35d8f85b7f7cfcad49360843b86a774cc79b024ef3500c73
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/zMnd8XtcwSM/uplcv?utm_term=cbse+maths+deleted+syllabus+for+class+10+pdf
- https://preprodpcb.com/userfiles/files/10487412852.pdf
- https://loan-financial.com/wp-content/plugins/super-forms/uploads/php/files/aba52a9df78cbc6d12dc3da7006edb32/25310268596.pdf
- https://nnkcreations.com/userfiles/file/gozuxadowilosotanes.pdf
- https://www.entornopublicitario.com/wp-content/plugins/super-forms/uploads/php/files/905d967cfb3a42110affcea0da6d0e8f/pefab.pdf
- http://files.ibiza-ferien.de/file/wugudiroju.pdf
- http://dayuntang.com/assets/uploads/ckedit/files/20210920212834.pdf
- https://tebra.si/userfiles/file/97311712606.pdf
- https://proetcontra.hu/userfiles/file/14255111606.pdf
- https://hram-uspeniya.ru/ckfinder/userfiles/files/geriperigerulojulanebu.pdf
- https://magicdiscoradio.com/userfiles/file/tezix.pdf
- http://thaiboxes.com/piceditor/file/60715671686.pdf
- https://szelvedojavitasmiskolc.hu/files/files/lekazisaluresanemugitiz.pdf
- http://rsti.biz/files/fck/file/76319784289.pdf
- http://accronline.com/userfiles/file/87006708526.pdf
- http://relaxzenter.com/uploads/files/24336062221.pdf
- http://minhtoangalaxyhotel.vn/app/webroot/files/ckfinder/files/gojefikitom.pdf
- http://ibtaker.ps/userfiles/file/75143670552.pdf
- http://z500.si/files/toxuwodalez.pdf
- http://abcgsgeds.friendship-match.com/upload/files/33745081077.pdf
- http://www.nachtruhe.info/up/files/85375266023.pdf
- http://evo-models.com/uploads/userfiles/files/nobupezisugig.pdf
- http://dzirerealtors.com/uploads/12884205065.pdf
- http://namlinhchisapa.com/userfiles/image/file/gukajama.pdf
- http://jeanthompson.nl/ckfinder/userfiles/files/64326476162.pdf
Embedded domains
- feedproxy.google.com
- preprodpcb.com
- loan-financial.com
- nnkcreations.com
- www.entornopublicitario.com
- files.ibiza-ferien.de
- dayuntang.com
- hram-uspeniya.ru
- magicdiscoradio.com
- thaiboxes.com
- rsti.biz
- accronline.com
- relaxzenter.com
- abcgsgeds.friendship-match.com
- www.nachtruhe.info
- evo-models.com
- dzirerealtors.com
- namlinhchisapa.com
- jeanthompson.nl
- www.w3.org
- purl.org
- ns.adobe.com
- tebra.si
- proetcontra.hu
- szelvedojavitasmiskolc.hu
Embedded IP addresses
- 57.155.101.212
- 74.179.77.204
- 52.110.12.53
- 52.110.12.25
- 4.247.188.233
- 135.233.95.144
- 4.144.132.223
- 104.46.162.224
- 74.178.240.51
- 20.231.239.246
- 72.154.7.104
- 203.26.79.13
- 4.230.171.124
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report