MALICIOUS — 0eba2f41935ca1bb613dcb501d496c2be5a6ec0ee1801b35a156acec2800f47c
MALICIOUS — 0eba2f41935ca1bb613dcb501d496c2be5a6ec0ee1801b35a156acec2800f47c is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the REvil family. 6 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0eba2f41935ca1bb613dcb501d496c2be5a6ec0ee1801b35a156acec2800f47c - SHA-1:
9c4b36c1a58b46f8584e1a28ae1a62afba75e9e0 - MD5:
24461fb9418eed5fb641d303b0820ded - ssdeep:
1536:dOuk7LX5tVtpLDtbGSH2pz6ffPRHcXa1W0nHTCLfp32OY:guqjTVBGSH2cHR8K1W2HToc - TLSH:
T11438C0F31197DD8CBA8FAF539EA7329D6086C3C86035DB655488732C98AC6AE3F50400 - Submitted as: 0eba2f41935ca1bb613dcb501d496c2be5a6ec0ee1801b35a156acec2800f47c
- File type: pdf · Size: 81413 bytes
- Verdict: malicious (95/100) · Family: REvil
Detections (6 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- YARA: Trellix/McAfee ATR: ATR_REvil_Sodinokibi
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!24461FB9418E
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Trellix/McAfee ATR flagged ATR_REvil_Sodinokibi (rule
ATR_REvil_Sodinokibi) - engine signal, weight 0.35, confidence 0.70 - Embedded link rated suspicious by URL analysis: https://nakubinigana.weebly.com/uploads/1/3/1/3/131379761/3363103.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://botokaw.ru/strik?utm_term=what%2527s+a+good+toaster+oven+to+buy, https://nakubinigana.weebly.com/uploads/1/3/1/3/131379761/3363103.pdf, https://74269c25-1731-4359-90d4-804f54ef9c1c.filesusr.com/ugd/b5973a_23c4c4843b9d4138a2282912d6659a54.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://botokaw.ru/strik?utm_term=what%2527s+a+good+toaster+oven+to+buy
- https://nakubinigana.weebly.com/uploads/1/3/1/3/131379761/3363103.pdf
- https://74269c25-1731-4359-90d4-804f54ef9c1c.filesusr.com/ugd/b5973a_23c4c4843b9d4138a2282912d6659a54.pdf?index=true
- https://efa91360-7c21-416c-9d60-3189e0beb381.filesusr.com/ugd/42ffc7_7cc8f58d083744a7b0f2cc8186a05ebc.pdf?index=true
- https://cdn.sqhk.co/lisupixiwe/iohjjig/unable_to_login_uber_driver_app.pdf
- https://cdn.sqhk.co/nazutupim/dnqMeib/41538450574.pdf
- http://nosinoski.shop/sofewumezagadelipijugs08g.pdf
- https://b7af6bb9-01eb-4839-ab56-764651de4344.filesusr.com/ugd/2486b5_00ce23d0e9f8409faec5f15e2f44c826.pdf?index=true
- https://fotaluxig.weebly.com/uploads/1/3/5/9/135973299/lopetulegate-doxudezuviwi-rimaj.pdf
- https://girawosanisab.weebly.com/uploads/1/3/0/7/130740609/777340.pdf
- http://wupidubame.mywebcommunity.org/28258274932.pdf
- https://lukujoluge.weebly.com/uploads/1/3/4/8/134864233/8733468.pdf
- https://rojurunonujimos.weebly.com/uploads/1/3/5/3/135325454/7d662c37.pdf
- http://fakaripeti.xyz/albany_county_family_court_forms0z7se.pdf
- https://cda84be5-0c54-4c05-8389-97bb004c798d.filesusr.com/ugd/fa9f00_7dffb12f37ad4e5ba733eaa8703e74f9.pdf?index=true
- http://gimemuwet.mypressonline.com/dewiregi.pdf
- https://cdn.sqhk.co/gemukojev/yghqxV1/mulufuxa.pdf
- https://6cbe2f5c-748b-4bc6-b691-25a968a47885.filesusr.com/ugd/d6b5da_1b4bf5a9c97442a3904faf49d234bf80.pdf?index=true
- https://3edbbcf3-b5b1-446e-9630-835d38fa79e0.filesusr.com/ugd/6908d7_f03e83627bff480ea12ae2ef1f6a1004.pdf?index=true
- http://lizoguxumugef.mywebcommunity.org/fiwemakirafolu.pdf
- https://bd7a0a6f-bbfd-49cc-ba41-c3f2778102d9.filesusr.com/ugd/9ea91e_bc3e836939a64bac8cb25a9d9bf6b66e.pdf?index=true
- https://1de4b56a-3309-4767-83a2-f1bb1ea7c594.filesusr.com/ugd/a6e5e9_61a18b74f94d436da8eea3058dfce991.pdf?index=true
- http://form-lnstagramverifiedbadges.com/solo_strikes_destiny_2w9xgt.pdf
- http://rexonina.medianewsonline.com/programmable_logic_controllers_erickson.pdf
- http://mizejodaf.mywebcommunity.org/stock_market_live_graph_today.pdf
Embedded domains
- botokaw.ru
- nakubinigana.weebly.com
- 74269c25-1731-4359-90d4-804f54ef9c1c.filesusr.com
- efa91360-7c21-416c-9d60-3189e0beb381.filesusr.com
- cdn.sqhk.co
- nosinoski.shop
- b7af6bb9-01eb-4839-ab56-764651de4344.filesusr.com
- fotaluxig.weebly.com
- girawosanisab.weebly.com
- wupidubame.mywebcommunity.org
- lukujoluge.weebly.com
- rojurunonujimos.weebly.com
- fakaripeti.xyz
- cda84be5-0c54-4c05-8389-97bb004c798d.filesusr.com
- gimemuwet.mypressonline.com
- 6cbe2f5c-748b-4bc6-b691-25a968a47885.filesusr.com
- 3edbbcf3-b5b1-446e-9630-835d38fa79e0.filesusr.com
- lizoguxumugef.mywebcommunity.org
- bd7a0a6f-bbfd-49cc-ba41-c3f2778102d9.filesusr.com
- 1de4b56a-3309-4767-83a2-f1bb1ea7c594.filesusr.com
- form-lnstagramverifiedbadges.com
- rexonina.medianewsonline.com
- mizejodaf.mywebcommunity.org
- poroda.site
- in-step.shop
More REvil samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report