SUSPICIOUS — bexox.pdf
SUSPICIOUS — bexox.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
e3b560f8080e4a02c7b643ebc898a10fad1425d004f47cec6821b056cfd2d984 - SHA-1:
72d77c2cdee9a99c6119450afef73084022193d1 - MD5:
5ba36e1ca5867e63adffe0dc688aeacd - ssdeep:
768:JCgGzpDne8xjjLWEitlsyjmk2ZxxkPR2u9ul4kzACi6sn2itymm12xyER:hGFDeSrnZxwRMl4Si6y2i2kyER - TLSH:
T109339EF350DBED8C7F8AAB036DBA1465214AC38C7126976044CC736DC8BC6BD6E01A61 - Submitted as: bexox.pdf
- File type: pdf · Size: 51549 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=the%20codex%20gigas%20english%20pdf, https://cdn-cms.f-static.net/uploads/4383579/normal_5f8e93255da65.pdf, https://cdn-cms.f-static.net/uploads/4393356/normal_5f900828bb4fc.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=the%20codex%20gigas%20english%20pdf
- https://cdn-cms.f-static.net/uploads/4383579/normal_5f8e93255da65.pdf
- https://cdn-cms.f-static.net/uploads/4393356/normal_5f900828bb4fc.pdf
- https://cdn-cms.f-static.net/uploads/4367650/normal_5f8d361b88b94.pdf
- https://cdn-cms.f-static.net/uploads/4377098/normal_5f8ceba687919.pdf
- https://cdn.shopify.com/s/files/1/0440/8098/8310/files/bejoti.pdf
- https://cdn.shopify.com/s/files/1/0499/3122/3202/files/vagisevivadim.pdf
- https://uploads.strikinglycdn.com/files/81727d00-52a6-49fe-8664-b10d271805fc/puxefasurok.pdf
- https://uploads.strikinglycdn.com/files/fe489420-2660-4ac0-8078-b3ec45251e7a/pudepotitelonezulul.pdf
- https://uploads.strikinglycdn.com/files/0d947c5c-5744-4682-82e7-18b9edc73b0d/jufipakib.pdf
- https://uploads.strikinglycdn.com/files/fa78aa60-350e-49ef-88a3-074a88243633/lusigitavevuseneribidabeg.pdf
- https://uploads.strikinglycdn.com/files/63e25597-a235-4b98-ab18-76644b55f0c6/terrarium_particle_sprinters.pdf
- https://uploads.strikinglycdn.com/files/5ba1d6f8-9caa-40a0-b528-bbc332533d21/husqvarna_fs400lv_parts_manual.pdf
- https://uploads.strikinglycdn.com/files/9ec3aef9-2e33-4dfc-863c-fca3939da480/19302785424.pdf
- https://uploads.strikinglycdn.com/files/7b716719-d0b8-4bd0-ad69-752d04b067ba/wedipuzuk.pdf
- https://uploads.strikinglycdn.com/files/d64e3759-33c5-4e4a-b169-993c2297d9d3/misititabiluzitejeto.pdf
- https://uploads.strikinglycdn.com/files/8261734d-4918-4270-98bc-c45d248ac631/nivemezufutaresetixekej.pdf
- https://uploads.strikinglycdn.com/files/fbc72060-077e-4416-99d0-7bf72e38562f/30374086315.pdf
- https://uploads.strikinglycdn.com/files/61e1013e-e382-45ad-af3d-98faa86e64b6/lebevopogoxuze.pdf
- https://uploads.strikinglycdn.com/files/5de88dec-ae0e-448f-bc81-bc52e00736f2/91604832936.pdf
- https://uploads.strikinglycdn.com/files/fd6eb972-cf19-4817-a285-8d6ad46d394e/fefol.pdf
- https://s3.amazonaws.com/mijedusovineti/cloud_computing_security_risk_assessment.pdf
- https://s3.amazonaws.com/jutenojamega/ugc_net_sociology_books_in_hindi.pdf
- https://s3.amazonaws.com/vonuxagupeduze/kavog.pdf
- https://s3.amazonaws.com/susopuzupure/pebesodonikisafivub.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report