SUSPICIOUS — dafegig.pdf
SUSPICIOUS — dafegig.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f6056c106cbc79e92f7283f2b8ac45264c147dd878da58b58bc99f5daa8e0312 - SHA-1:
f8307b7f68f7a57c516c2412c26d40d19e6a8a32 - MD5:
2a7f129759d94a4ebdb19361519ce826 - ssdeep:
768:cgGzpDepsc15DGiIU5PiROv2IEMbkjRNMtK6tQAyQYX/yS7prFI56:5GF6pf/fh4jRNMA6tQAyQYBprFI56 - TLSH:
T15D339EF35097ED8C7A4B6B439EAB0589644AC38C313696A005DC7B2CC4B86FD6F41A61 - Submitted as: dafegig.pdf
- File type: pdf · Size: 48025 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=silabario%20de%20san%20miguel%20arcangel, https://cdn-cms.f-static.net/uploads/4365591/normal_5f872ca3179be.pdf, https://cdn-cms.f-static.net/uploads/4370051/normal_5f886430a37ee.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=silabario%20de%20san%20miguel%20arcangel
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f872ca3179be.pdf
- https://cdn-cms.f-static.net/uploads/4370051/normal_5f886430a37ee.pdf
- https://cdn-cms.f-static.net/uploads/4366306/normal_5f88a926422d6.pdf
- https://uploads.strikinglycdn.com/files/9184cfd8-67c4-4b69-9641-1ee0dabd0a2a/mopafakafitazog.pdf
- https://uploads.strikinglycdn.com/files/ba72d290-6aa8-4be5-a53e-b002bff70526/kopigotakew.pdf
- https://uploads.strikinglycdn.com/files/4f286559-010f-4311-9636-7f4469fe60e6/29366311145.pdf
- https://uploads.strikinglycdn.com/files/064e29bb-f78e-44e3-b4f8-383467c690ca/13947262554.pdf
- https://uploads.strikinglycdn.com/files/5a9b67ee-ccf0-4bf0-aa68-63acec3a5cbb/vofusosos.pdf
- https://uploads.strikinglycdn.com/files/ccf11a22-872d-4e9a-8504-0f809ffb68f1/lokibeluxobufo.pdf
- https://uploads.strikinglycdn.com/files/dfd4ed54-718f-4708-84d2-92cc145fdbd5/rapodababozoti.pdf
- https://uploads.strikinglycdn.com/files/93d22bf5-8f2b-4331-bf46-968a8bf0451e/41295012392.pdf
- https://uploads.strikinglycdn.com/files/cadf86b1-4365-4660-aed3-8f15635ff29b/zezenokapegilupovunixad.pdf
- https://uploads.strikinglycdn.com/files/f076893e-3927-4f68-a5b8-70dacbc8f2b7/1664962684.pdf
- https://uploads.strikinglycdn.com/files/71ad7194-7e48-4a46-9b9c-8e0588abfc04/8256156590.pdf
- https://bewupoterefi.weebly.com/uploads/1/3/1/3/131380107/3181650.pdf
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/5813424f593ac5.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/b894c7ed849c995.pdf
- https://fevixivosetakub.weebly.com/uploads/1/3/2/6/132681861/temiluf-renafelo.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/debizikirapanas.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- bewupoterefi.weebly.com
- pigogokeda.weebly.com
- besiwalufeg.weebly.com
- fevixivosetakub.weebly.com
- vuxozajuje.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report