MALICIOUS — lojaw.pdf
MALICIOUS — lojaw.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fd3895fccc96846587fbeb0051c81a053f4394dfb1bf3ffe5b5884b592dccfe6 - SHA-1:
6bfde8da21da26e252f2f31994484538e1b0ed9f - MD5:
a1db8e09827e286ba08c10e193652ffa - ssdeep:
3072:aXyMODWjUwAjo8aNZ/gAoi/DWzB3TE/HIaytfhWlPO:aXyJajUwAzaX5oial3AIayVv - TLSH:
T18F3BD0F321E7ED0CB2C7EB43B9DA52686049D7982172EAD45088BA6CC4BC97D7F10650 - Submitted as: lojaw.pdf
- File type: pdf · Size: 110262 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://otdelkamos.ru/wp-content/plugins/super-forms/uploads/php/files/2c9114eb6a02b0c65c7073ede5956057/5524635488.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://www.aluvascientific.com/UserFiles/file/libesefewodolal.pdf, http://onlineticketreview.com/images/file/92321668946.pdf, http://www.jcca.co.in/wp-content/plugins/formcraft/file-upload/server/content/files/1608c3d748af2f---16357441368.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/3CAf4wW3hvY/uplcv?utm_term=research+methodology+objective+questions+for+phd+entrance
- http://www.aluvascientific.com/UserFiles/file/libesefewodolal.pdf
- http://onlineticketreview.com/images/file/92321668946.pdf
- http://www.jcca.co.in/wp-content/plugins/formcraft/file-upload/server/content/files/1608c3d748af2f---16357441368.pdf
- http://mundori.com/js/ckfinder/userfiles/files/wifabumubesimijanawiku.pdf
- https://avvocatoboretti.it/file/67451074594.pdf
- http://hdurmuslar.com/images_upload/files/77493160018.pdf
- https://otdelkamos.ru/wp-content/plugins/super-forms/uploads/php/files/2c9114eb6a02b0c65c7073ede5956057/5524635488.pdf
- http://topopentertainment.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607e42a4b435e---bupagisuvogetigil.pdf
- http://www.anjhimayath.com/upload/file/pudajinulo.pdf
- http://jmlukanich.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/zetaladegusifodevenero.pdf
- https://www.adcgrain.com/wp-content/plugins/super-forms/uploads/php/files/d0f4146b9622329000ae7166a4bf0b85/13748582673.pdf
- http://gnatowski.pl/attachments/file/jemurosuribefipusufam.pdf
- http://poolpoint.be/uploads/file/nevok.pdf
- http://www.ibadirect.com/wp-content/plugins/formcraft/file-upload/server/content/files/160be621c1cdae---71909995459.pdf
- http://andreevmag.com/wp-content/plugins/super-forms/uploads/php/files/4dc4941e118e2eb1518781750bd807b7/mogeki.pdf
- https://celovechurch.org/wp-content/plugins/super-forms/uploads/php/files/d06212b00ec51b346560212b3b917aa0/85505498081.pdf
- https://sitebyside.ru/wp-content/plugins/super-forms/uploads/php/files/999ef7fce2c1e8f91bb392ef02f97be7/vodubu.pdf
- http://www.cenlajobinator.com/siteuploads/editorimg/file/kodamonanuwem.pdf
- http://slphs66.com/clients/e/e6/e62fa13cff665df70d7481f632b33819/File/jogev.pdf
- https://hafa-verein.de/wp-content/plugins/super-forms/uploads/php/files/08f60fe80bc6473681716890fa9ee045/96056334857.pdf
- http://benetworkingpro.com/ckfinder/userfiles/files/kajewurige.pdf
- http://inwallendorf.de/userfiles/file/nugojizulip.pdf
- https://www.verpoort-bouw.be/wp-content/plugins/formcraft/file-upload/server/content/files/160bde592d7cbe---zejudenaj.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- www.aluvascientific.com
- onlineticketreview.com
- www.jcca.co.in
- mundori.com
- avvocatoboretti.it
- hdurmuslar.com
- otdelkamos.ru
- topopentertainment.com
- www.anjhimayath.com
- jmlukanich.com
- www.adcgrain.com
- gnatowski.pl
- poolpoint.be
- www.ibadirect.com
- andreevmag.com
- celovechurch.org
- sitebyside.ru
- www.cenlajobinator.com
- slphs66.com
- hafa-verein.de
- benetworkingpro.com
- inwallendorf.de
- www.verpoort-bouw.be
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report