MALICIOUS — lijurogatolurelirew.pdf
MALICIOUS — lijurogatolurelirew.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the REvil family. 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1e029cd96e747eea26c273d923f0da7c29684be06af17361d3ed989cadd6b6f8 - SHA-1:
b27acfec9271bdefd5f01c583278d089a02d7e45 - MD5:
2528b3309c85c6f7d8b3fac495203d94 - ssdeep:
1536:StnhOU4Lvl0qlw+JIiJn67otXshCW6wF7KLDRAIgW7ZiUINWspORFgRNUf:mE3zl0qlwsXCuwZGlfZ7IURiRi - TLSH:
T16238CFF3219BDD9C72878F0758A70169A48AD3C861719A90418C776CD87CAFDBF14A13 - Submitted as: lijurogatolurelirew.pdf
- File type: pdf · Size: 81985 bytes
- Verdict: malicious (95/100) · Family: REvil
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- YARA: Trellix/McAfee ATR: ATR_REvil_Sodinokibi
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Trellix/McAfee ATR flagged ATR_REvil_Sodinokibi (rule
ATR_REvil_Sodinokibi) - engine signal, weight 0.35, confidence 0.70 - Embedded link rated suspicious by URL analysis: http://qbcar.ru/ckfinder/userfiles/files/wozelevifazigepire.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://qbcar.ru/ckfinder/userfiles/files/wozelevifazigepire.pdf, http://cerritos.songhakbbq.com/uploads/files/pobezu.pdf, http://bora.su/ckfinder/userfiles/files/71676694250.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/DOqCt-cVA4I/uplcv?utm_term=india+no+1+smartphone+brand+2021
- http://qbcar.ru/ckfinder/userfiles/files/wozelevifazigepire.pdf
- http://cerritos.songhakbbq.com/uploads/files/pobezu.pdf
- http://bora.su/ckfinder/userfiles/files/71676694250.pdf
- https://noukos.gr/wp-content/plugins/formcraft/file-upload/server/content/files/1612f46dc07ae7---85300486350.pdf
- https://bonvoyageindia.in/ckfinder/userfiles/files/72407717050.pdf
- https://orkhaconstruction.com/wp-content/plugins/super-forms/uploads/php/files/mg1jaed5fem83gn4jp48mnhl1i/20301581323.pdf
- http://ms-krmelin.cz/app/webroot/files/files/31961247913.pdf
- http://pierrevillers.fr/mairie_files/file/detitel.pdf
- http://doremimarlikinsaat.com/userfiles/file/34639024619.pdf
- http://www.contectrade.hu/fckfiles/file/xifilulabivakitanosizosaj.pdf
- http://crmrealty360degree.in/userfiles/file/40148758792.pdf
- https://fatheragneliti.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613879b46cf20---nafomamu.pdf
- https://philly.drinkpoint.com/uploads/files/jutojuj.pdf
- https://www.ciabrini-immobilier.com/wp-content/plugins/super-forms/uploads/php/files/bclf7n788fhhogcalkpfq8ptdr/nawoj.pdf
- http://studiozoppini.com/userfiles/files/duvinenutinaxowof.pdf
- https://adamant54.ru/userfiles/files/xozenivoparewader.pdf
- http://gocchame.vn/app/webroot/img/uploads/files/gobogasijufekefaki.pdf
- https://hobbes-group.com/upload/files/86823092540.pdf
- http://erex.hu/upload/file/jutazurirevofijuzoporux.pdf
- http://hamishehbaharcarpet.com/My_Project/Hamishe_bahar/ahar_img/files/56696930382.pdf
- https://magicdiscoradio.hu/userfiles/file/89421959885.pdf
- https://tkpmission.org/wp-content/plugins/formcraft/file-upload/server/content/files/16131d7437ace4---20611567089.pdf
- http://onlytech-tunisie.com/userfiles/file/tonorigimafu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- qbcar.ru
- cerritos.songhakbbq.com
- bora.su
- bonvoyageindia.in
- orkhaconstruction.com
- pierrevillers.fr
- doremimarlikinsaat.com
- crmrealty360degree.in
- fatheragneliti.com
- philly.drinkpoint.com
- www.ciabrini-immobilier.com
- studiozoppini.com
- adamant54.ru
- hobbes-group.com
- hamishehbaharcarpet.com
- tkpmission.org
- onlytech-tunisie.com
- www.w3.org
- purl.org
- ns.adobe.com
- noukos.gr
- ms-krmelin.cz
- www.contectrade.hu
- gocchame.vn
More REvil samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report