MALICIOUS — 09f57082a2d904244c9e03847ec0ab5724d54aca77836ffc71c8dc65100306fa
MALICIOUS — 09f57082a2d904244c9e03847ec0ab5724d54aca77836ffc71c8dc65100306fa is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the REvil family. 5 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
09f57082a2d904244c9e03847ec0ab5724d54aca77836ffc71c8dc65100306fa - SHA-1:
08003fe8ed00f4720269f84fbecb4cf96959a744 - MD5:
de56425985c9533ce6255b58eaf2795b - imphash:
acc4f8a03813bbb9cae35e8706064635 - ssdeep:
196608:ObPk5HyC8k5h/wDdEoNiV4I/WWwA7mFMglbPk5HyC8k5h/wDdEoNiV4I/WWwA7m:ObPk5HPhJCFMglbPk5HPhJCFMg - TLSH:
T1F6685CA3920D634ACED0E9B9E4296B5D100BBDD873B51FDC6AA39008D2D24D7857E0D3 - Submitted as: 09f57082a2d904244c9e03847ec0ab5724d54aca77836ffc71c8dc65100306fa
- File type: pe · Size: 7960417 bytes
- Verdict: malicious (96/100) · Family: REvil
Detections (5 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): MinGW
- ClamAV (daily): Win.Trojan.Agent-448770
- YARA: Trellix/McAfee ATR: ATR_REvil_Sodinokibi
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Detect It Easy (packer/type): DIE:MinGW
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Agent-448770 (rule
Win.Trojan.Agent-448770) - engine signal, weight 0.90, confidence 0.95 - YARA: Trellix/McAfee ATR flagged ATR_REvil_Sodinokibi (rule
ATR_REvil_Sodinokibi) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:MinGW (rule
DIE:MinGW) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.pinkworld.com, http://www.youporn.com, http://www.redtube.com - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: MinGW - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.pinkworld.com
- http://www.youporn.com
- http://www.redtube.com
- http://www.assparade.com/
- http://www.freeav.com/
- http://www.gnu.org/licenses/gpl.html
- http://bibnum.bnf.fr/WARC/WARC_ISO_28500_version1_latestdraft.pdf
- http://netpreserve.org/warc/1.0/revisit/identical-payload-digest
- http://www.metalinker.org/
- https://www.openssl.org/docs/faq.html
- http://www.w3.org/2000/xmlns/
- http://www.w3.org/XML/1998/namespace
- https://secure.comodo.net/CPS0A
- https://secure.comodo.net/CPS0C
- http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
- http://crt.comodoca.com/COMODORSAAddTrustCA.crt0$
Embedded domains
- www.pinkworld.com
- www.youporn.com
- www.redtube.com
- www.assparade.com
- www.freeav.com
- openssl.org
- gnu.org
- www.gnu.org
- xemacs.org
- bibnum.bnf.fr
- netpreserve.org
- www.metalinker.org
- www.openssl.org
- www.w3.org
- crl.usertrust.com
- crt.usertrust.com
- secure.comodo.net
- crl.comodoca.com
- crt.comodoca.com
File paths
- c:\w
More REvil samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report