SUSPICIOUS — mamelapinadubinuvivo.pdf
SUSPICIOUS — mamelapinadubinuvivo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
6c149fe7f2f5043ff44773510851e359e267172c252c84e8d411bdf58e14ee41 - SHA-1:
d3d8e3cec983b056996f8fc49f496bd0d743f797 - MD5:
02a2ea14b7876a041a2054abab89077e - ssdeep:
768:MgGzpDGo3MPpC8wVGm8BxkIFmJG1fWLdaBofP2swUwvUZgyobFkT:JGFy/x5HEWofP2sOcZVobFkT - TLSH:
T13231AFF7A4EBED8D3A8A5F136DAA015D6086C38C611386A014CC767CD0BC6FD6E41962 - Submitted as: mamelapinadubinuvivo.pdf
- File type: pdf · Size: 40857 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=activate%20showtime%20spotify%20student, https://cdn-cms.f-static.net/uploads/4373516/normal_5f8af89518713.pdf, https://cdn-cms.f-static.net/uploads/4383806/normal_5f908d906c783.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=activate%20showtime%20spotify%20student
- https://cdn-cms.f-static.net/uploads/4373516/normal_5f8af89518713.pdf
- https://cdn-cms.f-static.net/uploads/4383806/normal_5f908d906c783.pdf
- https://wokugosag.weebly.com/uploads/1/3/4/3/134339956/6506010.pdf
- https://cdn-cms.f-static.net/uploads/4372737/normal_5f8ba1f4e85d9.pdf
- https://cdn-cms.f-static.net/uploads/4379722/normal_5fa443b5146c1.pdf
- https://dugizade.weebly.com/uploads/1/3/4/4/134442098/93c502.pdf
- https://cdn-cms.f-static.net/uploads/4392210/normal_5f9fb8795ec52.pdf
- https://cdn-cms.f-static.net/uploads/4417313/normal_5f9e83fa22e57.pdf
- https://fekudumubaf.weebly.com/uploads/1/3/2/6/132681201/d35f11698e4898.pdf
- https://cdn-cms.f-static.net/uploads/4365540/normal_5f8fc9871188c.pdf
- https://cdn-cms.f-static.net/uploads/4411480/normal_5fa49be1e9515.pdf
- https://uploads.strikinglycdn.com/files/2c988c28-ba3c-47a7-a32f-40278a4f1722/78091945046.pdf
- https://cdn-cms.f-static.net/uploads/4377407/normal_5f943d24c91aa.pdf
- https://pisekubil.weebly.com/uploads/1/3/4/3/134322001/xuletidufutomuni.pdf
- https://cdn-cms.f-static.net/uploads/4372105/normal_5f91c21c4920b.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- wokugosag.weebly.com
- dugizade.weebly.com
- fekudumubaf.weebly.com
- uploads.strikinglycdn.com
- pisekubil.weebly.com
- 2006.it
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report