MALICIOUS — 43874775643.pdf
MALICIOUS — 43874775643.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
e8266a0239725d519bc7d6c52458c85e23f9b780e5a68fcd447ebf2e26cfa893 - SHA-1:
4771c7edd8e9e86f5211e415f8c2ce45208405ea - MD5:
29f4de9d43d21168eace2776d0c84f8d - ssdeep:
1536:RPy8DF1IZfTqTzF459Q1iRCLn90dK3CFl5PW87VYVmVqN7WApO6EYis:g8UIgQKCLn9TI5LGMqNK6EC - TLSH:
T18439D0F3715BED1CB7876B03AAB6116860CAE7881563DB504188B2BCD6BC97C7E00A51 - Submitted as: 43874775643.pdf
- File type: pdf · Size: 84384 bytes
- Verdict: malicious (99/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Contacted 29 external host(s) at runtime (7 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://stewsites.com/wp-content/plugins/super-forms/uploads/php/files/1841701dbd410a4fd0ea8bb0ce5169f1/36241370641.pdf, https://panama4d.com/contents//files/kuzukunaw.pdf, https://gjbuyerbroker.com/userfiles/file/70954919230.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9700 behavior events · 1 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/2cbcf400-ac8d-4d86-9d69-c7f0dff56d2e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/2cbcf400-ac8d-4d86-9d69-c7f0dff56d2e?P1=1787098213&P2=404&P3=2&P4=BZ%2b%2fzG0mbdcekm10jB742FnmKDG7TjjjDaMxU7BCWpJCc4tpfz6q56WDSrfqJ%2fa%2bc9MxJrVd%2fn9E9UAhvBbC2g%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/58b2a9b1-8570-476c-a7c2-f7ab0a20fbf9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/58b2a9b1-8570-476c-a7c2-f7ab0a20fbf9?P1=1787098285&P2=404&P3=2&P4=XbZIAFYRumtGFRfTHK%2f1KFRY7SQvgO8ylnW%2fQ3V%2fgrcEXCH89OIGB5QL51mi9tzKn8GL1ktlUuZUuR1GcxlUiA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- 23.40.52.209
- 23.11.37.157
- 20.190.167.19
Dropped files
- /opt/CAPEv2/storage/analyses/30910/files/f851079cbffc58aebe46e119d3b0b481c2f9de07fc454c811fd3038cc3424159 -
f851079cbffc58aebe46e119d3b0b481c2f9de07fc454c811fd3038cc3424159 - /opt/CAPEv2/storage/analyses/30910/files/f085caba7d2f90146392a885334efe9cbedb0d1b6a19606b39a4d1b832aedc10 -
f085caba7d2f90146392a885334efe9cbedb0d1b6a19606b39a4d1b832aedc10 - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.jLQ3xMrz0u -
e2bcff73358bbd6d8c883a736a71bfa30ed530547b9f756091172ee6a5b3368f
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/1KS0DP0cxss/uplcv?utm_term=fordyce+spots+on+labia+home+remedies
- https://stewsites.com/wp-content/plugins/super-forms/uploads/php/files/1841701dbd410a4fd0ea8bb0ce5169f1/36241370641.pdf
- https://panama4d.com/contents//files/kuzukunaw.pdf
- https://gjbuyerbroker.com/userfiles/file/70954919230.pdf
- https://webmodels.studio/wp-content/plugins/formcraft/file-upload/server/content/files/1611311fd67d33---gazeviwux.pdf
- http://learnersdigest.org/userfiles/file/vufosoxafolupesoz.pdf
- http://arebiatours.com/uploads/files/faxofirenigefevuli.pdf
- https://burkina-businessschool.com/business_school/uploads/file/20821167299.pdf
- http://www.photobreak.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160b4ea13157e7---bajuvorozetutefowa.pdf
- http://amwordpress.org/wp-content/plugins/formcraft/file-upload/server/content/files/160c6a00b2f51c---5251031390.pdf
- https://fieldofgreen.com/wp-content/plugins/super-forms/uploads/php/files/00c7a2fbfd4f51bcc73147761c20cf0d/66947862871.pdf
- http://52fotki.ru/ckfinder/userfiles/files/52230988739.pdf
- https://sasalidayanisma.org/uploads/file/rujugasodafekejumo.pdf
- https://zweiund40.com/wp-content/plugins/super-forms/uploads/php/files/hb2bg5acfk4sru3nm4p8frfseh/9332380198.pdf
- https://kolodezrus.ru/wp-content/plugins/super-forms/uploads/php/files/a68e660d6e302dfa046e65c221190b7e/jewezaxenubomijopus.pdf
- https://yourlightingbrand.com/wp-content/plugins/super-forms/uploads/php/files/eee2e265e34589a028506a997028bf41/99620558202.pdf
- http://dd-eng.com/files/files/20844685084.pdf
- https://nmcs.ca/userfiles/files/rubitusikepanuzilujotuwif.pdf
- http://stauarchitetti.eu/userfiles/files/38533805017.pdf
- http://www.pointcookelectrician.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1606f51fd77f43---98470545580.pdf
- https://alamansyria.com/userfiles/file/89365377860.pdf
- https://kicksomeglass.com/wp-content/plugins/super-forms/uploads/php/files/f7cdd2f6817598ffc8de466cfb8c41ff/vefikizosa.pdf
- http://sts-logistika.ru/wp-content/plugins/super-forms/uploads/php/files/cce2eb83898faaa0f151a9fcfa1217d9/93389351125.pdf
- https://atx-stroy.ru/wp-content/plugins/super-forms/uploads/php/files/4f3d63512daa73fae4133a4dfd4729b4/zoforewukuwifekalifi.pdf
- https://camping-du-lac-dijon.com/fichiers/xukisapeketaluvigip.pdf
Embedded domains
- feedproxy.google.com
- stewsites.com
- panama4d.com
- gjbuyerbroker.com
- learnersdigest.org
- arebiatours.com
- burkina-businessschool.com
- www.photobreak.com.br
- amwordpress.org
- fieldofgreen.com
- 52fotki.ru
- sasalidayanisma.org
- zweiund40.com
- kolodezrus.ru
- yourlightingbrand.com
- dd-eng.com
- nmcs.ca
- stauarchitetti.eu
- www.pointcookelectrician.com.au
- alamansyria.com
- kicksomeglass.com
- sts-logistika.ru
- atx-stroy.ru
- camping-du-lac-dijon.com
- www.w3.org
Embedded IP addresses
- 52.123.252.242
- 20.42.179.192
- 52.110.12.33
- 4.230.171.124
- 135.233.95.144
- 52.168.112.66
- 52.123.129.14
- 40.99.133.226
- 172.178.240.162
- 74.178.76.44
- 203.26.79.13
- 51.116.246.105
- 92.223.78.30
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report