SUSPICIOUS — rexogosuwubegifub.pdf
SUSPICIOUS — rexogosuwubegifub.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d7a9ea74980717496814a47d75a3d10034e0d8a7833c4cbf5fb2ff35c8a97fa9 - SHA-1:
c251feb01edfb01501381712db505363c6a2e8a5 - MD5:
236a735f91d53262d35bbc098b0ecc4e - ssdeep:
1536:+GFlp3sauVh2xrRG8ZIYVD63ZQ03/fOO:nFlp3Mz2/GPYZMZpL - TLSH:
T14F33AFF71093ED4D7A8EAB539DBB225C918AC38821369760048C772ED47C6FD6F016A1 - Submitted as: rexogosuwubegifub.pdf
- File type: pdf · Size: 50586 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=ielts%20writing%20task%202%20topics%20with%20ans, https://uploads.strikinglycdn.com/files/0bbb62aa-d12d-4150-b506-8a57385b34b5/.pdf, https://uploads.strikinglycdn.com/files/f61b916d-f089-4c08-ac9e-c1f9a1d299e6/16995620156.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=ielts%20writing%20task%202%20topics%20with%20ans
- https://uploads.strikinglycdn.com/files/0bbb62aa-d12d-4150-b506-8a57385b34b5/.pdf
- https://uploads.strikinglycdn.com/files/f61b916d-f089-4c08-ac9e-c1f9a1d299e6/16995620156.pdf
- https://uploads.strikinglycdn.com/files/c666bb57-e7ae-431b-9f7a-2235c1fbd4cf/simple_rental_agreement_or_residential_lease_word_doc.pdf
- https://uploads.strikinglycdn.com/files/c73cba88-9bc3-47d2-aeb5-2ea7907fbc19/dungeons_and_dragons_5e_cleric_build.pdf
- https://uploads.strikinglycdn.com/files/fb460050-e214-4dcb-ba1b-ffbaf517f22d/22273530461.pdf
- https://uploads.strikinglycdn.com/files/1f40cb8d-749b-481b-adb1-b6076f64ebda/40182282695.pdf
- https://uploads.strikinglycdn.com/files/ff574026-bbd6-4f64-96dd-5bf177160c23/pivegimajodixovaredez.pdf
- https://uploads.strikinglycdn.com/files/33216c98-381e-4215-b04d-380ca4ceb88d/mofodowilofabosupojideka.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f8a9288a41ca.pdf
- https://cdn-cms.f-static.net/uploads/4374957/normal_5f8a85dde4647.pdf
- https://cdn-cms.f-static.net/uploads/4366321/normal_5f87e98b1c1a2.pdf
- https://cdn-cms.f-static.net/uploads/4368242/normal_5f8a5a839360b.pdf
- https://cdn-cms.f-static.net/uploads/4366381/normal_5f8713b986172.pdf
- https://uploads.strikinglycdn.com/files/8b44c6fd-1c96-48dc-b55c-7b8b155c7551/sanoderofakolid.pdf
- https://uploads.strikinglycdn.com/files/72a2fe6d-d5ed-4a85-9bd4-e29ef8ae0beb/vebilavezadif.pdf
- https://uploads.strikinglycdn.com/files/76581df4-462c-4567-9838-ece04f6fc943/tebuwo.pdf
- https://uploads.strikinglycdn.com/files/29ebcd9b-8923-403f-b707-3af924126b0a/mc_livinho_retrato_youtube.pdf
- https://uploads.strikinglycdn.com/files/6b87fc5a-877d-4dcf-86f6-e7ccf87b91bb/24696692724.pdf
- https://uploads.strikinglycdn.com/files/9a868530-fa0e-44a9-92e2-d779ff3269ac/37964961581.pdf
- https://uploads.strikinglycdn.com/files/f5fb9a9f-d0b0-4810-b0b1-ab852b752958/xelufefun.pdf
- https://uploads.strikinglycdn.com/files/8c773a78-52b1-44ec-99d3-b1557e616a8b/bopinazunomoz.pdf
- https://uploads.strikinglycdn.com/files/323fb1d4-8b22-4ffb-a537-761b7789f06c/58366072968.pdf
- https://uploads.strikinglycdn.com/files/e62c6ff0-0e51-45e3-b449-6cdf5b150e15/linopaxexewikexerebovuzim.pdf
- https://cdn.shopify.com/s/files/1/0495/1392/2728/files/warner_stained_glass_free_patterns.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report