MALICIOUS — 86323467521.pdf
MALICIOUS — 86323467521.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100). 3 of 23 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
d093f4677fb36ce44f9b150a9170dd5cf9b3630d1e0c8cd8ec0b2ff686ca1880 - SHA-1:
b5328b16423f7bdb333f6ff240f6a234e3a74f23 - MD5:
8bab4c933270cd19407cb282ad6d7af7 - ssdeep:
1536:ixqeTHtWhYIQtxn9E9gNrhm2AbLhwWypOlWWxk8FUZq78P4QJ8zI1:LeTzvn9E9KQ2aLzlDkyFjHa - TLSH:
T18138D1F32187DE4C378BDF07ADEA11585486EF883563E9604188B96CD67C5BEAE00E11 - Submitted as: 86323467521.pdf
- File type: pdf · Size: 82380 bytes
- Verdict: malicious (93/100)
Detections (3 of 23 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 93/100 is the fusion of 8 weighted signals:
- Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Contacted 23 external host(s) at runtime (3 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded link rated suspicious by URL analysis: http://gdbchurch.com/clients/43262/File/lebipivuvuxapitiboveti.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://gdbchurch.com/clients/43262/File/lebipivuvuxapitiboveti.pdf, https://hssanesteban.cl/files/xevamiv.pdf, https://atolab.it/wp-content/plugins/super-forms/uploads/php/files/12913b3254444b4f3bd2564d7abcad67/gaseruwiwojomazexezinoxik.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9727 behavior events · 1 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
- 192.168.122.114
- 150.171.22.17
Dropped files
- /opt/CAPEv2/storage/analyses/24631/files/d8d278b05452eec26df7c18bda92856f3e2791cc73a8c863643f117ab8a33a4a -
d8d278b05452eec26df7c18bda92856f3e2791cc73a8c863643f117ab8a33a4a - /opt/CAPEv2/storage/analyses/24631/files/df3660b236c2698d9e28964eaa892f6b108f3aa818810b1093f239db3d8d30f5 -
df3660b236c2698d9e28964eaa892f6b108f3aa818810b1093f239db3d8d30f5 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.phLwJrF4Cf -
fa7675eaabc497005d1597d093aeee5a30b6ea2d9a999ab2076efeb33099515f
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/1xuhb7AK25c/uplcv?utm_term=how+to+put+border+on+word+document
- http://gdbchurch.com/clients/43262/File/lebipivuvuxapitiboveti.pdf
- https://hssanesteban.cl/files/xevamiv.pdf
- https://atolab.it/wp-content/plugins/super-forms/uploads/php/files/12913b3254444b4f3bd2564d7abcad67/gaseruwiwojomazexezinoxik.pdf
- https://hirurgija.me//files/12399552252.pdf
- http://alliance-ltd.com/userfiles/17742093537.pdf
- http://greatwalledmond.com/ckfinder/userfiles/files/82004360549.pdf
- https://www.landalastadservice.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a624075fb67---47513735153.pdf
- https://oxfordjsr.com/userfiles/file/rajumidevi.pdf
- http://www.sunarnuricomuisvealisverismerkezi.com/wp-content/plugins/super-forms/uploads/php/files/ri6pvi7f775fsbufnfumabsrf6/54474443462.pdf
- http://nhadatv.com/webroot/img/files/85538032918.pdf
- http://www.leesii.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608d07db6580b---vixewojudopezisakisodufu.pdf
- http://pvsystexperts.com/wp-content/plugins/super-forms/uploads/php/files/pclc39ln23tcgrm3g6lssrmsb1/xelidefatupatadaxeli.pdf
- http://landonintergroup.com/ckfinder/userfiles/files/zurekodefepedufukexusimo.pdf
- https://secolink.sk/userfiles/file/sutarula.pdf
- http://renovfab-menuiserie.com/userfiles/file/dijezozuvilope.pdf
- http://www.gainerwindows.ca/wp-content/plugins/super-forms/uploads/php/files/7sr86p65sbt6unklsqohe2o6a1/pifasopupilemit.pdf
- http://www.fsnn.se/wp-content/plugins/formcraft/file-upload/server/content/files/160ac2d9feae57---66772963649.pdf
- https://pilotcenter.gr/wp-content/plugins/super-forms/uploads/php/files/imsf0dh1e69fhu6u8l8o364ajs/99384198714.pdf
- https://comfortinnbarrie.com/phpsites/vertical_living/uploads/file/75918797199.pdf
- https://madeinstlucia.com/userfiles/files/lozebejovedudot.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- feedproxy.google.com
- gdbchurch.com
- atolab.it
- hirurgija.me
- alliance-ltd.com
- greatwalledmond.com
- www.landalastadservice.com
- oxfordjsr.com
- www.sunarnuricomuisvealisverismerkezi.com
- nhadatv.com
- www.leesii.com
- pvsystexperts.com
- landonintergroup.com
- renovfab-menuiserie.com
- www.gainerwindows.ca
- www.fsnn.se
- comfortinnbarrie.com
- madeinstlucia.com
- www.w3.org
- purl.org
- ns.adobe.com
- hssanesteban.cl
- secolink.sk
- pilotcenter.gr
Embedded IP addresses
- 172.67.208.133
- 74.178.240.61
- 52.110.12.55
- 4.230.171.124
- 125.56.205.42
- 20.247.184.197
- 72.145.35.98
- 74.178.76.128
- 4.247.188.224
- 4.247.188.233
- 162.159.36.2
- 203.26.79.13
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report