SUSPICIOUS — rezukiwamid.pdf
SUSPICIOUS — rezukiwamid.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
9d120ecf4099f39aae986e92fdce8d76a36a1bd0b906fc8db6c7365d8923f1d7 - SHA-1:
bcd216ca439540006ce35207cbf7d68c6a7073ea - MD5:
f3f6ac88ce6c7a2cc614c32aac0143aa - ssdeep:
768:AgGzpDyenpFBVCo8PTrQYa7GASGQsvw0rgCLENEi6svdZxCVWIhbo9:NGFWeCa7GA+aj4m+vdZxgHhbo9 - TLSH:
T1D2328EF34197EC8C7A8B6F139EBB1258614BD38D613296A048C8776CD07C6EE7E10A11 - Submitted as: rezukiwamid.pdf
- File type: pdf · Size: 45666 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=warkop%20dki%20reborn%20jangkrik%20boss%20part%201%20mp4, https://cdn.shopify.com/s/files/1/0436/9770/1017/files/pasisubirezizasagifoxale.pdf, https://cdn.shopify.com/s/files/1/0439/1282/2939/files/watexunojifuwibuxuki.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=warkop%20dki%20reborn%20jangkrik%20boss%20part%201%20mp4
- https://cdn.shopify.com/s/files/1/0436/9770/1017/files/pasisubirezizasagifoxale.pdf
- https://cdn.shopify.com/s/files/1/0439/1282/2939/files/watexunojifuwibuxuki.pdf
- https://cdn.shopify.com/s/files/1/0496/4581/3924/files/yo_kai_watch_jibanyan_medal.pdf
- https://cdn.shopify.com/s/files/1/0484/4696/3862/files/is_south_pacific_capitalized.pdf
- https://cdn.shopify.com/s/files/1/0431/7731/2407/files/3.5_as_a_improper_fraction.pdf
- https://site-1040263.mozfiles.com/files/1040263/bunigewolesigamesasidan.pdf
- https://site-1041766.mozfiles.com/files/1041766/seril.pdf
- https://site-1041926.mozfiles.com/files/1041926/82896140877.pdf
- https://site-1043487.mozfiles.com/files/1043487/sinukarobosixo.pdf
- https://site-1039801.mozfiles.com/files/1039801/jopopiraxuvofokem.pdf
- https://site-1039668.mozfiles.com/files/1039668/43098082347.pdf
- https://uploads.strikinglycdn.com/files/edb0fed8-3c97-4dd9-a31b-979a12181a9c/19106937075.pdf
- https://uploads.strikinglycdn.com/files/8c73518a-e161-45ad-b2ae-f5a788bb69e8/58935266422.pdf
- https://uploads.strikinglycdn.com/files/04265a4b-23b6-4f6e-9897-7749e394e056/98180756227.pdf
- https://uploads.strikinglycdn.com/files/db89d412-aa96-4f2b-a7b9-a56d5be8873c/81967017260.pdf
- https://uploads.strikinglycdn.com/files/e1969c63-844e-46bc-a815-147dd96cb16b/60374378995.pdf
- https://uploads.strikinglycdn.com/files/587ef904-fdc8-4ec1-bfcb-10f41c82216c/murefogopuwur.pdf
- https://cdn.shopify.com/s/files/1/0486/2456/6432/files/pufejirusoze.pdf
- https://cdn.shopify.com/s/files/1/0431/5598/0450/files/corel_photoimpact_x3_activation_code_crack.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- site-1040263.mozfiles.com
- site-1041766.mozfiles.com
- site-1041926.mozfiles.com
- site-1043487.mozfiles.com
- site-1039801.mozfiles.com
- site-1039668.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report