MALICIOUS — 59345441693.pdf
MALICIOUS — 59345441693.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ef7a88b1d3dec2508c0b37a22f27e18fd2a3853743bcca9d215fe0bf46d837af - SHA-1:
4a96b5e2276c1cd36a45f4ca4f138e7f080b4703 - MD5:
1212f1cae37c03b34da23bc2c69b6254 - ssdeep:
1536:TB1j81CXqXUK7oiXk34qLylmMZYIscAWHpOvTWa0aPqH9yOFS4rDfw8:N1j81wYp7oiXY4/m6YIVYv/0amcO0+DX - TLSH:
T1DE38D0F370ABDD8CB3C7CF0729BA11B85499E3CA5162DA6004C8776CC5786BD6E509A0 - Submitted as: 59345441693.pdf
- File type: pdf · Size: 80979 bytes
- Verdict: malicious (98/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Embedded network infrastructure: https://pistant.ru/uplcv?utm_term=the+king+of+fighters+xiv+download+apk, https://www.denisonlandscaping.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614bd60047580---wopelutodekidizo.pdf, http://katour.ru/admin/ckfinder/userfiles/files/2724647659.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 6 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
999 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- 135.233.95.80 US · Des Moines · AS8075 Microsoft Limited
- 224.0.0.251
- ff02::fb
- 10.240.0.1
- 169.254.255.255
- ff02::16
- ff02::2
- 40.84.97.4 US · Boydton · AS8075 Microsoft Corporation
- 224.0.0.22
- 52.168.117.174 US · Chantilly · AS8075 Microsoft Corporation
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.h4Q6ciTvMa -
048503dff0d16752b605bc669e1792e7fb32a67b0f7524ca08ee94031b1615ff
Embedded URLs
- https://pistant.ru/uplcv?utm_term=the+king+of+fighters+xiv+download+apk
- https://www.denisonlandscaping.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614bd60047580---wopelutodekidizo.pdf
- http://katour.ru/admin/ckfinder/userfiles/files/2724647659.pdf
- http://inruho.ru/ckfinder/userfiles/files/kefakomanag.pdf
- http://finsura-lifedirect.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/161469c3a5cfb3---damar.pdf
- https://powermailer.in/userfiles/file/wotujojesaledariru.pdf
- http://letnipohar.cz/upload/file/17456479981.pdf
- http://urbancollab.com/userfiles/Proj_Name/files/53144150682.pdf
- https://a-guskov.ru/uploads/files/lonepazuterataja.pdf
- http://myflora888.com/ck_files/files/rokilefeb.pdf
- https://unitedfightalliance.jordanadams.com/ckfinder/userfiles/files/23761530719.pdf
- http://zpb-maciejewski.pl/upload/fck/file/12377744634.pdf
- http://h-p-n.fr/catalogue_dynamique/file/komibatunepeginigexi.pdf
- http://suspensionestg.mx/userfiles/file/37542496761.pdf
- http://food-cloud.com/home/food-cloud/www/site/site/data/files/29640100444.pdf
- http://modelkyujin.com/wp-content/plugins/formcraft/file-upload/server/content/files/16137ba0cee1d8---25797850649.pdf
- https://gryf-wet.pl/ckfinder/userfiles/files/zimunitukinowadi.pdf
- http://sineadstone.com/userfiles/file/moxagenov.pdf
- http://tradeweb.es/userfiles/file/jazemefoke.pdf
- http://matras-devison.ru/upload/file/93184061631.pdf
- https://sportuna.be/ckfinder/userfiles/files/89145707092.pdf
- http://findmecakes.com/userfiles/files/pagirufibobubaxolimuvo.pdf
- http://wumag.pl/userfiles/file/9262590619.pdf
- https://fullmagicweekend.com/ckfinder/userfiles/files/98630894210.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- pistant.ru
- www.denisonlandscaping.com
- katour.ru
- inruho.ru
- finsura-lifedirect.com.au
- powermailer.in
- urbancollab.com
- a-guskov.ru
- myflora888.com
- unitedfightalliance.jordanadams.com
- zpb-maciejewski.pl
- h-p-n.fr
- suspensionestg.mx
- food-cloud.com
- modelkyujin.com
- gryf-wet.pl
- sineadstone.com
- tradeweb.es
- matras-devison.ru
- sportuna.be
- findmecakes.com
- wumag.pl
- fullmagicweekend.com
- www.w3.org
- purl.org
Embedded IP addresses
- 135.233.95.80
- 40.84.97.4
- 52.168.117.174
- 34.160.111.145
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report