SUSPICIOUS — f3e174e43.pdf
SUSPICIOUS — f3e174e43.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100), attributed to the REvil family. 3 of 50 detection engines flagged it.
Identification
- SHA-256:
1796b294ba213ee289c103b6473cde3d0bfc2b6a828345bd8a1db50ad7b3cb15 - SHA-1:
6eff867458b0798657837762cfd2afbde0db2125 - MD5:
3a4c5469ea67fc5bc81ca5b9a3050230 - ssdeep:
768:QgGzpDXpQAXHaTeu32+gUrotSLlB6bJdXkYINzNLepqOdO9s5lT3:9GFDpc4IrYHdO9sfT3 - TLSH:
T1B1319DF750ABEC4C7E8A9F13ADA715566089D34D2232E3A0008C772CC5BC6BDBE50861 - Submitted as: f3e174e43.pdf
- File type: pdf · Size: 42797 bytes
- Verdict: suspicious (58/100) · Family: REvil
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- YARA: Trellix/McAfee ATR: ATR_REvil_Sodinokibi
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- YARA: Trellix/McAfee ATR flagged ATR_REvil_Sodinokibi (rule
ATR_REvil_Sodinokibi) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://gettraff.ru/wb?keyword=jack%20kerouac%20dharma%20bums%20pdf, https://cdn.shopify.com/s/files/1/0268/7349/5734/files/61683338469.pdf, https://cdn.shopify.com/s/files/1/0495/4941/0456/files/mekovojav.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=jack%20kerouac%20dharma%20bums%20pdf
- https://cdn.shopify.com/s/files/1/0268/7349/5734/files/61683338469.pdf
- https://cdn.shopify.com/s/files/1/0495/4941/0456/files/mekovojav.pdf
- https://cdn.shopify.com/s/files/1/0438/5066/2053/files/speelschema_wk_2020_download.pdf
- https://cdn.shopify.com/s/files/1/0501/8697/7441/files/breville_avance_toaster_manual.pdf
- https://cdn.shopify.com/s/files/1/0437/8987/7405/files/guide_unlimited_clash_of_clans_2019.pdf
- https://uploads.strikinglycdn.com/files/c3d248ca-8cbf-453a-89a1-c7554ac3e582/2234306148.pdf
- https://uploads.strikinglycdn.com/files/deef411b-6ae7-44cb-9888-40eea4e3e9b5/11519956556.pdf
- https://cdn-cms.f-static.net/uploads/4380237/normal_5f8aae3393006.pdf
- https://cdn-cms.f-static.net/uploads/4366949/normal_5f8786562c451.pdf
- https://cdn-cms.f-static.net/uploads/4369654/normal_5f9126356ec9c.pdf
- https://cdn-cms.f-static.net/uploads/4387420/normal_5f948ba0ea21b.pdf
- https://cdn-cms.f-static.net/uploads/4367905/normal_5f8f6c651fc0f.pdf
- https://s3.amazonaws.com/petikamov/bowuwevexojijesor.pdf
- https://s3.amazonaws.com/pusori/american_revolution_battles_worksheet.pdf
- https://s3.amazonaws.com/vitelitubovuluj/anselm_the_ontological_argument.pdf
- https://s3.amazonaws.com/zurovajij/49946570100.pdf
- https://s3.amazonaws.com/gupuso/20182543510.pdf
- https://s3.amazonaws.com/dedinavesute/tuzutigizo.pdf
- https://s3.amazonaws.com/susopuzupure/angulos_y_rectas_1o_eso.pdf
- https://cdn.shopify.com/s/files/1/0432/9675/1771/files/citar_mla_online.pdf
- https://cdn.shopify.com/s/files/1/0432/0978/5499/files/orient_blackswan_school_atlas_download.pdf
- https://cdn.shopify.com/s/files/1/0482/2564/8797/files/putugopevevijerisuni.pdf
- https://cdn.shopify.com/s/files/1/0486/0752/7077/files/6288185155.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
More REvil samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report