SUSPICIOUS — mefumemubipivadat.pdf
SUSPICIOUS — mefumemubipivadat.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
20606a67002f7f8c687acb516a3422393412631afff5730272fd408d1ffed189 - SHA-1:
438922f6cf3130b61a93f758c74c7a81e3367b6a - MD5:
75e49a49f6eb1704eff0a9a6b4329b5f - ssdeep:
768:XgGzpDwV+AEUCRv5irPn+d7QyjUFBaRKXXs0H2eho/c/WK:wGF0wXNZMr+dU6UFBaRKns0HDho/c/WK - TLSH:
T1C5319DF395A7DD8C7A86AF039EEA1558A14AC78C7132C3604588772CC4BC6FD6E04E61 - Submitted as: mefumemubipivadat.pdf
- File type: pdf · Size: 42436 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=guess+who+electronic+game+instructions, https://site-1037124.mozfiles.com/files/1037124/lumapotalizixesunidubuma.pdf, https://site-1044017.mozfiles.com/files/1044017/livosalapodanol.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=guess+who+electronic+game+instructions
- https://site-1037124.mozfiles.com/files/1037124/lumapotalizixesunidubuma.pdf
- https://site-1044017.mozfiles.com/files/1044017/livosalapodanol.pdf
- https://site-1040132.mozfiles.com/files/1040132/30763414353.pdf
- http://farilonil.kemiesho.com/uploads/1/3/0/8/130874030/9166673.pdf
- http://sijufa.dongguru.com/uploads/1/3/1/3/131398234/3044a07b8.pdf
- https://uploads.strikinglycdn.com/files/701a2aac-0875-46fe-aa43-ee655a41d8e6/welenurutitukibasikaki.pdf
- https://uploads.strikinglycdn.com/files/fb46a38d-27b2-4157-bdaa-36b1d1a26c86/85432668015.pdf
- https://uploads.strikinglycdn.com/files/1f1452a8-8097-4b70-a34b-e88fc734fa7b/ruwepekapofexe.pdf
- https://uploads.strikinglycdn.com/files/445258a8-e650-4ba9-b25a-7589a52ccad6/87024252584.pdf
- https://uploads.strikinglycdn.com/files/112a14b4-e89c-482e-8341-4091b6512216/12994881076.pdf
- https://uploads.strikinglycdn.com/files/4fa2e9e9-ad4f-49d0-b982-f8b385568a24/86013246413.pdf
- https://uploads.strikinglycdn.com/files/e322e557-b4a7-430b-9623-a3cbb70fdd21/6676508595.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1037124.mozfiles.com
- site-1044017.mozfiles.com
- site-1040132.mozfiles.com
- farilonil.kemiesho.com
- sijufa.dongguru.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report