MALICIOUS — lilop.pdf
MALICIOUS — lilop.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a0af575d82c3ecee588f42caee266a075aeca62a5c3f598c59d48625d7121bd6 - SHA-1:
88ec53e307e4223e5857e2bb1ac49fdafdd5e0e9 - MD5:
c295e0bf76d02edbb2faffa79eab03e7 - ssdeep:
1536:HVq1/b0e83J+p3oiRXqNlDhxwO59L2P4g6NWAcWxApOGzWb4H3koMXf7K:10b0Ny9qNlDhxf9L8gZ93GiA3kPu - TLSH:
T15D38C0E7609BED8C374A9F8368BA1268604BD3883172DB60514C763CD9BC6BD7F10561 - Submitted as: lilop.pdf
- File type: pdf · Size: 77645 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://studiodrago.eu/userfiles/files/62336024823.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://advantagelic.com/singhania/downloads/file/96519988654.pdf, http://fortlauderdalelimorental.net/wp-content/plugins/formcraft/file-upload/server/content/files/16082a1e2b2ba0---vopiwif.pdf, http://pr-jam.com/ckfinder/userfiles/files/16972106447.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/3CAf4wW3hvY/uplcv?utm_term=psr+ew410+manual
- https://advantagelic.com/singhania/downloads/file/96519988654.pdf
- http://fortlauderdalelimorental.net/wp-content/plugins/formcraft/file-upload/server/content/files/16082a1e2b2ba0---vopiwif.pdf
- http://pr-jam.com/ckfinder/userfiles/files/16972106447.pdf
- http://katour.ru/admin/ckfinder/userfiles/files/52528746235.pdf
- http://senn1962reunion.com/clients/2/2f/2fc2c703930c5c120d54ce0350dd22c7/File/vepuk.pdf
- http://njchemland.com/upload/files/begabemifajotexumepe.pdf
- http://studiodrago.eu/userfiles/files/62336024823.pdf
- https://manenshop.com/upload/files/ledipil.pdf
- https://kaxtongroup.com/home5/maxconne/public_html/kaxtongroup/assets/images/newspostimages/files/96363209583.pdf
- https://web-sila.ru/wp-content/plugins/super-forms/uploads/php/files/252c509d5e5e638ac65511ccf73b77e3/99419549105.pdf
- http://ashole.hu/UserFiles/File/xuduzeni.pdf
- https://celebicatering.com/upload/ckfinder/files/gelijeda.pdf
- http://co-wemart.com/careeruserfiles/file/88658608614.pdf
- http://neodentpetrosino.it/userfiles/files/57000059667.pdf
- https://arte-salon.ru/upload_picture/fusirupimanabuzuzitixagig.pdf
- http://www.findvoters.com/userfiles/file/52499789999.pdf
- https://harpethvalleypto.org/wp-content/plugins/super-forms/uploads/php/files/bb6b0a3e227794880f3e42ccc9fe7445/90573765030.pdf
- http://karate-talence.com/newsite/userfiles/files/fakobivixujurojebekixan.pdf
- https://autosofortkauf.ch/wp-content/plugins/super-forms/uploads/php/files/ivdur1cp7s19ncr2t5s3ce1q3b/nekavanaguludubuzow.pdf
- http://pileshoppen.dk/userfiles/file/difazibemidigaxo.pdf
- http://zs-oilfieldequip.ru/d/files/7732126180.pdf
- https://phoenixknights.co.uk/wp-content/plugins/super-forms/uploads/php/files/9d1f759ee9b3e307cb9525a371d8e5f7/37184324211.pdf
- http://anm-av.de/uploads/files/27863602404.pdf
- http://61kidsclub.com/userfiles/file/zenobagaxefifevalu.pdf
Embedded domains
- feedproxy.google.com
- advantagelic.com
- fortlauderdalelimorental.net
- pr-jam.com
- katour.ru
- senn1962reunion.com
- njchemland.com
- studiodrago.eu
- manenshop.com
- kaxtongroup.com
- web-sila.ru
- celebicatering.com
- co-wemart.com
- neodentpetrosino.it
- arte-salon.ru
- www.findvoters.com
- harpethvalleypto.org
- karate-talence.com
- autosofortkauf.ch
- zs-oilfieldequip.ru
- phoenixknights.co.uk
- anm-av.de
- 61kidsclub.com
- alconburyreunion.com
- acornschoolcharleston.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report