MALICIOUS — 17077682541.pdf
MALICIOUS — 17077682541.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the REvil family. 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
83f8ba4cb41369a8f61846ea68e8252504fdb08bad6949d6fdffd7b1186c4a9b - SHA-1:
2b1d6c37b73f63dbc8814b9682ec40ce364a8752 - MD5:
fcb88f4eec160793a94ef864361d2d24 - ssdeep:
1536:fj1XUJBU0OcG91/wz/GOlG3vK5ElxkhPWOpOwr9L7E3N0W5c59E0arjk6:5EtPG918/rw3CKlJwrZEdm8XZ - TLSH:
T1E038C0F360DBDD0D778B8B4775FB1198648AD2896162EB5000887B6CD8BC5BD7F01A90 - Submitted as: 17077682541.pdf
- File type: pdf · Size: 81580 bytes
- Verdict: malicious (97/100) · Family: REvil
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- YARA: Trellix/McAfee ATR: ATR_REvil_Sodinokibi
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://massimobertoarchitetto.com/userfiles/files/nanezonisutononolibizusew.pdf - network signal, weight 0.70, confidence 0.80
- YARA: Trellix/McAfee ATR flagged ATR_REvil_Sodinokibi (rule
ATR_REvil_Sodinokibi) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://www.inkfactory.pk/wp-content/plugins/formcraft/file-upload/server/content/files/161327d9eca7ab---pexerejigugo.pdf, http://jmk.kr/ckfinder/userfiles/files/89593698493.pdf, http://qlionshousing.ca/userfiles/file/tugajagebekajed.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/GLLx1DTH0VQ/uplcv?utm_term=transfer+files+from+android+to+pc+via+bluetooth
- https://www.inkfactory.pk/wp-content/plugins/formcraft/file-upload/server/content/files/161327d9eca7ab---pexerejigugo.pdf
- http://jmk.kr/ckfinder/userfiles/files/89593698493.pdf
- http://qlionshousing.ca/userfiles/file/tugajagebekajed.pdf
- https://leise.ru/admin/ckfinder/userfiles/files/27830808140.pdf
- http://gesundezellen.de/neu/userfiles/file/munikejunewabudefikax.pdf
- https://laplacedesstores.com/upload/file/tiwofedemol.pdf
- https://bongkartuantakur.com/contents/files/22699200252.pdf
- http://boekenwinkelindex.nl/images/uploads/vadexelenuwuvetulujube.pdf
- http://massimobertoarchitetto.com/userfiles/files/nanezonisutononolibizusew.pdf
- http://vino-charlie.cz/userfiles/file/vapemekusefowuvufol.pdf
- http://uptownchantilly.com/uploads/files/51536955431.pdf
- https://777mto.com/contents/files/vugusunapoge.pdf
- http://muabannhagiare.net/images/uploads/files/fiwanumuxigamuzunazudota.pdf
- http://logicparcel.net/uploadsEditorfile/suxabeduninuseboger.pdf
- https://cuatudongnhatrang.com/uploads/files/77126063000.pdf
- http://105chers.netsociality.com/upload/files/77120143519.pdf
- https://ofly.om-digitalsolutions.cn/upload/files/24843472659.pdf
- http://www.anclupnapoli.it/userfiles/file/zewabirejosibo.pdf
- http://docando.es/js/ckfinder/userfiles/files/fejexekajanoxezasaxidi.pdf
- https://lsp.od.ua/wp-content/plugins/super-forms/uploads/php/files/erfotcoj2gg09kl63la0g7rli2/moguweforeviletufobilaget.pdf
- http://fajni3333.fun4two.pl/uploads/assets/file/samun.pdf
- http://prttour.ca/FileData/ckfinder/files/20210902_6AE1A759E27DF0D3.pdf
- http://sotel-perm.ru/site/file/94643302027.pdf
- http://pinxedien.net/upload/files/sefosakosamixom.pdf
Embedded domains
- feedproxy.google.com
- jmk.kr
- qlionshousing.ca
- leise.ru
- gesundezellen.de
- laplacedesstores.com
- bongkartuantakur.com
- boekenwinkelindex.nl
- massimobertoarchitetto.com
- uptownchantilly.com
- 777mto.com
- muabannhagiare.net
- logicparcel.net
- cuatudongnhatrang.com
- 105chers.netsociality.com
- ofly.om-digitalsolutions.cn
- www.anclupnapoli.it
- docando.es
- lsp.od.ua
- fajni3333.fun4two.pl
- prttour.ca
- sotel-perm.ru
- pinxedien.net
- medarbindia.org
- www.w3.org
More REvil samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report