MALICIOUS — lavowe.pdf
MALICIOUS — lavowe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
e21af85bb2813ba110597fc7ee74a3ca05c48ebdc5e3878d896ae1e9945119c0 - SHA-1:
fba086cf94fbe40ff3f5b25a02156295abc02f8f - MD5:
c175f55a9f563f06d956fd6c9ead71cb - ssdeep:
1536:jxrfLo6MavwZMojlEtaIZgx8IjWatoT/KYZv+r2AE6xAamSEek7W0etJE0tIxjVR:24vftR2xvhG/Zvpl6WaKCtmjVzwr8b - TLSH:
T18739C0F3219BED4C764B9B435697125CB48EF3886132EA658088B76CC4BCBBDBE00551 - Submitted as: lavowe.pdf
- File type: pdf · Size: 87793 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://allytemp.ru/uplcv?utm_term=forensic+investigations+blood+spatter+worksheet+answers+fsb09, https://fo-prefectures.com/pages/files/5273029041.pdf, http://allycatering.com/userfiles/jijaputan.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://allytemp.ru/uplcv?utm_term=forensic+investigations+blood+spatter+worksheet+answers+fsb09
- https://fo-prefectures.com/pages/files/5273029041.pdf
- http://allycatering.com/userfiles/jijaputan.pdf
- http://ziepniekkalns.lv/wp-content/plugins/formcraft/file-upload/server/content/files/160be88c2aadde---68007711342.pdf
- https://www.hagensmarketing.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bf86e211ceb---1353171294.pdf
- https://fiberglasssupplydepot.com/userfiles/file/dikufilekiwiralaruzug.pdf
- https://uaqbakery.com/wp-content/plugins/formcraft/file-upload/server/content/files/16090f9d67ed98---zixepumik.pdf
- https://webmodeli.com/wp-content/plugins/formcraft/file-upload/server/content/files/16074af397651a---tipanepojunew.pdf
- https://www.femregenx.co.za/wp-content/plugins/super-forms/uploads/php/files/oi8l70f8i5l5k7rshajm8uq9fv/wexupedewudelodelunuko.pdf
- http://thanhlamresort.vn/wp-content/plugins/formcraft/file-upload/server/content/files/160afe832c2711---70348805232.pdf
- https://amagi.la/wp-content/plugins/formcraft/file-upload/server/content/files/1609b3428f10f3---gofuraziviza.pdf
- https://eurouniversal.eu/ckfinder/userfiles/files/denilumep.pdf
- https://yournew.site/wp-content/plugins/super-forms/uploads/php/files/3giku3nkhmd11u47tn46csu928/54249482096.pdf
- http://chronicles.ae/userfiles/files/65996215.pdf
- http://amtutoring.com/clients/865321/File/15647542113.pdf
- https://misionesmedellin2030.com/wp-content/plugins/super-forms/uploads/php/files/e72fpuvftovdoiv8efoh9upj62/37109252715.pdf
- https://keluargamimpi.com/contents//files/11899032700.pdf
- https://baodinhsolar.com/wp-content/plugins/super-forms/uploads/php/files/rubr3la04d56q340aire6qu23o/suxezurasefokivutizotiv.pdf
- http://bezpieczna-strefa.pl/wp-content/plugins/super-forms/uploads/php/files/2692bfa65e0048849f0fc298d085f965/xogil.pdf
- http://www.theagentpipeline.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607b8caec0823---pelebubiga.pdf
- http://zelene-centrum.cz/webpagebuilder/ckfinder/userfiles/files/nalaniwunurebotomojaluje.pdf
- http://www.iamgoingto1996.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607ae02369958---jiwuvi.pdf
- https://toromecanicorodeo.com/files/xadakuxinatuw.pdf
- http://lecieldesandes.fr/ckfinder/userfiles/files/pofat.pdf
- https://cristiandellavedova.com/wp-content/plugins/super-forms/uploads/php/files/cus2ph18kk06o43ffmpn54o5m5/wozujibeke.pdf
Embedded domains
- allytemp.ru
- fo-prefectures.com
- allycatering.com
- www.hagensmarketing.com
- fiberglasssupplydepot.com
- uaqbakery.com
- webmodeli.com
- www.femregenx.co.za
- eurouniversal.eu
- yournew.site
- amtutoring.com
- misionesmedellin2030.com
- keluargamimpi.com
- baodinhsolar.com
- bezpieczna-strefa.pl
- www.theagentpipeline.com
- www.iamgoingto1996.com
- toromecanicorodeo.com
- lecieldesandes.fr
- cristiandellavedova.com
- www.w3.org
- purl.org
- ns.adobe.com
- ziepniekkalns.lv
- thanhlamresort.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report