MALICIOUS — f5eb4ca1644ff5f6dfc56c263159de2f1856d6f921ef5c8c2505fd7e8764e05b
MALICIOUS — f5eb4ca1644ff5f6dfc56c263159de2f1856d6f921ef5c8c2505fd7e8764e05b is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 4 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
f5eb4ca1644ff5f6dfc56c263159de2f1856d6f921ef5c8c2505fd7e8764e05b - SHA-1:
7d6b1ef0a55b922cf2823a0a3205ede387fa76b5 - MD5:
013758ddae33616954ce8b85edc65ed2 - ssdeep:
1536:nx7C3uRrqoOhihOpyEuOkUCCVaLI5VJItiZA7PIWxqeB3qWwpOSlP+:x9RrlOhiSECVacLeAS7PMGdSw - TLSH:
T1BC39CFF321D3ED5CBA5A9B077DDA51AD7049E3D82672DE1080C8BAAC81384FD7E04A41 - Submitted as: f5eb4ca1644ff5f6dfc56c263159de2f1856d6f921ef5c8c2505fd7e8764e05b
- File type: pdf · Size: 86111 bytes
- Verdict: malicious (99/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded link rated suspicious by URL analysis: http://castudio.eu/userfiles/files/nawukaja.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://shamayachts.com/upload/file/46056531312.pdf, http://kurier48.pl/files/userfiles/file/gebuf.pdf, http://longarmquiltacademy.net/fckeditor/userfiles/file/lilefoninev.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 5 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
987 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- 40.126.14.161
- ff02::1:3
- 224.0.0.252
- 224.0.0.251
- ff02::fb
- 10.240.0.1
- 239.255.255.250
- 91.189.91.157
- 185.125.190.58
- ff02::1:2
- 224.0.0.22
- ff02::16
- ff02::1:ff12:3456
- 4.150.223.103 US · Des Moines · AS8075 Microsoft Corporation
- 74.179.77.204 US · Moses Lake · AS8075 Microsoft Corporation
- 255.255.255.255
- ff02::2
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.cb4e5ajI1M -
ee3c342bffb4209de9e4af43268838519a470ccd4e53056456ad036f4652f818
Embedded URLs
- https://feedproxy.google.com/~r/Gsjc/~3/TxADE9PCSUw/uplcv?utm_term=this+is+how+we+do+it+all+night
- http://shamayachts.com/upload/file/46056531312.pdf
- http://kurier48.pl/files/userfiles/file/gebuf.pdf
- http://longarmquiltacademy.net/fckeditor/userfiles/file/lilefoninev.pdf
- http://movesearchesuk.com/userfiles/file/xafevi.pdf
- http://songdolandmarkcity.com/userfiles/file/19355587475.pdf
- http://opalbiosciences.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613012609f02a---setowezevur.pdf
- http://bielwod.com/userfiles/file/wexopiladu.pdf
- https://venefoil.com/ckfinder/userfiles/files/lunumazuwefer.pdf
- http://pvvc.cz/files/60629841021.pdf
- http://castudio.eu/userfiles/files/nawukaja.pdf
- http://eggtesting.com/admin/uploads/file/badinafusapozopugujodebu.pdf
- http://coimbrasoftware.hu/images/uploads/files/mafosisifomarok.pdf
- https://tradegateindia.com/userfiles/file/40719759217.pdf
- https://stancijanegrin.com/UserFiles/files/71862721584.pdf
- http://problemconsulting.com/img/download/files/filivuzerupuru.pdf
- https://nulifeus.com/~nulife/userfiles/file/32148868346.pdf
- https://tpijobportal.com/ckeditor/ckfinder/userfiles/files/nafufut.pdf
- http://csc0731.com/userfiles/file/20210923082923_5s064l.pdf
- http://npcbalkan.net/ckeditor/ckfinder/userfiles/files/gexezepufunog.pdf
- http://customize.fr/fckeditor/editor/filemanager/connectors/php/img/Editor/file/14787267343.pdf
- https://www.ayersworthglen.com/wp-content/plugins/formcraft/file-upload/server/content/files/16145d3de79162---2113477680.pdf
- https://mindtrainingsystems.com/userfiles/file/xujesitemijalosidamidodi.pdf
- https://lrsinc.co/userfiles/file/waxipuporigesijedikexe.pdf
- https://speedwayinfo.hu/uploads/file/levavakadigexurupida.pdf
Embedded domains
- feedproxy.google.com
- shamayachts.com
- kurier48.pl
- longarmquiltacademy.net
- movesearchesuk.com
- songdolandmarkcity.com
- opalbiosciences.com
- bielwod.com
- venefoil.com
- castudio.eu
- eggtesting.com
- tradegateindia.com
- stancijanegrin.com
- problemconsulting.com
- nulifeus.com
- tpijobportal.com
- csc0731.com
- npcbalkan.net
- customize.fr
- www.ayersworthglen.com
- mindtrainingsystems.com
- lrsinc.co
- gaseg.com
- shesob.com
- www.w3.org
Embedded IP addresses
- 4.150.223.103
- 74.179.77.204
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report