SUSPICIOUS — normal_5f961aebb7ef0.pdf
SUSPICIOUS — normal_5f961aebb7ef0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100), attributed to the REvil family. 4 of 50 detection engines flagged it.
Identification
- SHA-256:
38bc62f49b52c55e112e21df75092f50e92e9c03dab12550e64a07efe312565a - SHA-1:
b3b2e5a69308bc451a3b111b71fb199ad4534752 - MD5:
21f799c867b9e3fee64632f90336b936 - ssdeep:
768:FgGzpDwpLScrrJOIiJGoY4GkD0h4YiwutF+ovNFWQSelIqWHlRGOiztwf6OYVMQZ:WGFkpVSGoYmJA8xwf6OwdtOUMrAld - TLSH:
T1DB339DF30097ED8C3A8F6F139EFA1159A18ED38961329361458C672CD1BC6ED6F10A91 - Submitted as: normal_5f961aebb7ef0.pdf
- File type: pdf · Size: 50377 bytes
- Verdict: suspicious (58/100) · Family: REvil
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- YARA: Trellix/McAfee ATR: ATR_REvil_Sodinokibi
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- YARA: Trellix/McAfee ATR flagged ATR_REvil_Sodinokibi (rule
ATR_REvil_Sodinokibi) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.cc/123?keyword=hamilton+beach+roaster+oven+instruction+manual, https://uploads.strikinglycdn.com/files/2f373c71-aacb-4cb5-ac9a-502aa1fe66ea/11453345084.pdf, https://uploads.strikinglycdn.com/files/265acfc6-b027-4946-b905-c6697d1ff73e/tumuxifepikaf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/123?keyword=hamilton+beach+roaster+oven+instruction+manual
- https://uploads.strikinglycdn.com/files/2f373c71-aacb-4cb5-ac9a-502aa1fe66ea/11453345084.pdf
- https://uploads.strikinglycdn.com/files/265acfc6-b027-4946-b905-c6697d1ff73e/tumuxifepikaf.pdf
- https://uploads.strikinglycdn.com/files/c3ff90f6-dea8-4552-9274-0f25d3ed8387/lazesizoja.pdf
- https://uploads.strikinglycdn.com/files/d6d89747-5297-470e-962e-fd2eb8cb3572/46609343610.pdf
- https://uploads.strikinglycdn.com/files/75987ab6-36b6-4fce-bf45-d6b83f9cc1e4/jerifisamid.pdf
- https://cdn-cms.f-static.net/uploads/4370740/normal_5f960d4388fed.pdf
- https://cdn-cms.f-static.net/uploads/4367912/normal_5f94fbbce1582.pdf
- https://cdn-cms.f-static.net/uploads/4392862/normal_5f8f88238393b.pdf
- https://cdn-cms.f-static.net/uploads/4369665/normal_5f886c4c73ad4.pdf
- https://cdn-cms.f-static.net/uploads/4377647/normal_5f8a325437846.pdf
- https://uploads.strikinglycdn.com/files/c3d02b8e-adb9-441a-80b3-4b7d82669c09/breville_bbm800xl_bread_maker_user_manual.pdf
- https://uploads.strikinglycdn.com/files/51499ed4-85fc-41ce-a41f-08f3f1529f11/wofakedinizosipatuzugipo.pdf
- https://cdn.shopify.com/s/files/1/0495/2906/1542/files/natezisegodiwow.pdf
- https://cdn.shopify.com/s/files/1/0498/7486/2247/files/gounod_messe_breve.pdf
- https://cdn.shopify.com/s/files/1/0482/7853/6356/files/asclepius_wellness_pvt_ltd_plan.pdf
- https://cdn.shopify.com/s/files/1/0434/0314/9479/files/xopefuxilefapojuzadelux.pdf
- https://cdn.shopify.com/s/files/1/0502/9416/1605/files/case_study_on_rainwater_harvesting.pdf
- https://cdn.shopify.com/s/files/1/0499/9898/7414/files/exploitation_of_natural_resources.pdf
- https://cdn.shopify.com/s/files/1/0501/9936/3764/files/18841500728.pdf
- https://cdn.shopify.com/s/files/1/0266/9117/4583/files/world_history_ancient_civilizations.pdf
- https://cdn.shopify.com/s/files/1/0435/8009/6667/files/99823848711.pdf
- https://cdn.shopify.com/s/files/1/0494/2263/1067/files/full_metal_dust_jacket_script.pdf
- https://xuguzopagar.weebly.com/uploads/1/3/4/4/134490213/c594f1d6fe0.pdf
- https://netaluzubik.weebly.com/uploads/1/3/0/8/130813777/4160206.pdf
Embedded domains
- ttraff.cc
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- xuguzopagar.weebly.com
- netaluzubik.weebly.com
- zelapagetuwuj.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
More REvil samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report