MALICIOUS — 66744572090.pdf
MALICIOUS — 66744572090.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
c2d369089c1eec6425f9591ed6e3bc56c51196b726c9e6db17f676c663f44aa3 - SHA-1:
37dfea7e1e1ae3cd97f3121ad84571a2f4373be1 - MD5:
919b03004406c4e10034a3a2a772fde0 - ssdeep:
1536:/GGth+OF8cfRJ2ZGaaPiW2XXRoEAblbvzOSWOpOaZEWahjDJ4LUYU6QuZr:uGWzaaXnRjABbLcaZiuYF4 - TLSH:
T1C138C0E330E7DC8C7B8B9F4339B9115CA48AE6486152EE904198B2ACD47C9FDBF10651 - Submitted as: 66744572090.pdf
- File type: pdf · Size: 83753 bytes
- Verdict: malicious (98/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Embedded link rated suspicious by URL analysis: http://ajisushionline.com/uploads/files/gapapapufanajativ.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://catamma.ru/uplcv?utm_term=roasted+cauliflower+and+broccoli+in+air+fryer, http://areawifi.com/DESARROLLO/userfiles/files/kajajiweronavotumiruteg.pdf, https://cspdental.com/wp-content/plugins/super-forms/uploads/php/files/5dbad0d935a1139c31ea9462733ded5c/mujekuj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
1071 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- none
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.cUD0B69rxV -
92698dd0936f130875b588fed221d3baa304fa0f2e07f84d29a028f4eca3bcf3
Embedded URLs
- https://catamma.ru/uplcv?utm_term=roasted+cauliflower+and+broccoli+in+air+fryer
- http://areawifi.com/DESARROLLO/userfiles/files/kajajiweronavotumiruteg.pdf
- https://cspdental.com/wp-content/plugins/super-forms/uploads/php/files/5dbad0d935a1139c31ea9462733ded5c/mujekuj.pdf
- http://ajisushionline.com/uploads/files/gapapapufanajativ.pdf
- https://www.cedicar.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c98fee4b94a---raxomowododiradovarowo.pdf
- http://kassa.pl/userfiles/file/bomonor.pdf
- https://personalloan2u.com/wp-content/plugins/super-forms/uploads/php/files/dabee7ac91c48e53ea6f64421bcb4c3a/bopoxasebojugosedazut.pdf
- https://llibreriaha.com/img/events/file/xetikijemizovazu.pdf
- http://technology-mp.it/userfiles/files/borowopiri.pdf
- https://chp-travel.ir/data/file/mufutaje.pdf
- http://a-range.ru/wp-content/plugins/formcraft/file-upload/server/content/files/16093a52a78920---18900421791.pdf
- http://volkshilfe-vlbg.at/images/content/files/49275143437.pdf
- http://mko-yug.ru/wp-content/plugins/super-forms/uploads/php/files/82e9c73accafe26ad943657b0ccec396/37843649451.pdf
- https://ooo-kenk.ru/userfiles/file/tatogulok.pdf
- http://hjtech.org/admin/upfile/file/64171591911.pdf
- http://artside.org/data/temp/file/32740742503.pdf
- http://metaglas.kr/userData/board/file/61289384397.pdf
- https://miamivanservice.net/wp-content/plugins/formcraft/file-upload/server/content/files/160ad57cb0c7ce---bibinalijuf.pdf
- http://agcslohian.com/userfiles/file/rudelulubetubev.pdf
- https://www.hadlowsecurityshutters.com/wp-content/plugins/super-forms/uploads/php/files/df57f37c55804d95ec983a263e4e45f4/devemoxutogojuzepi.pdf
- https://www.lang-mayer.de/wp-content/plugins/formcraft/file-upload/server/content/files/160cce320eb59a---nuvevorigigerasibu.pdf
- http://abwnickersonplaza.com/uploads/files/94965311982.pdf
- http://kazuma.ru/ckfinder/userfiles/files/46090027131.pdf
- http://naturalmis.com/userfiles/file/sevakuzawefuvudakaleza.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- catamma.ru
- areawifi.com
- cspdental.com
- ajisushionline.com
- www.cedicar.com
- kassa.pl
- personalloan2u.com
- llibreriaha.com
- technology-mp.it
- chp-travel.ir
- a-range.ru
- mko-yug.ru
- ooo-kenk.ru
- hjtech.org
- artside.org
- metaglas.kr
- miamivanservice.net
- agcslohian.com
- www.hadlowsecurityshutters.com
- www.lang-mayer.de
- abwnickersonplaza.com
- kazuma.ru
- naturalmis.com
- www.w3.org
- purl.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report