MALICIOUS — 2faaddb.pdf
MALICIOUS — 2faaddb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
709ea92fe9899038d5bce5b196722d8c11851178a287d04ddc0ed7990a3c14e0 - SHA-1:
bf17ac0656fe2bfbb17eee7cce323c0179f72dd8 - MD5:
651d5731b31f74f97a883ace02839a8d - ssdeep:
1536:HfGF2esT0GgKDdEY3J43S76GpEeD+ruJttyq3ubfufNpIWyO0cACVLljdF:uF2esT0GgKzMEPVubfuf3iCN3 - TLSH:
T17638B0F31197EC8C77CAAF47AEEB1199918AC789213696A045C47B6CC5BC2FC5E10E10 - Submitted as: 2faaddb.pdf
- File type: pdf · Size: 80466 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/fibaxizimudez.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=the%20crucible%20act%203%20and%204%20quiz, https://uploads.strikinglycdn.com/files/dcfbb456-fe86-4766-acee-04c319ee5f92/vinefinudomaba.pdf, https://uploads.strikinglycdn.com/files/8c7afae6-0002-4713-a24b-7b284592b23c/wonadas.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=the%20crucible%20act%203%20and%204%20quiz
- https://uploads.strikinglycdn.com/files/dcfbb456-fe86-4766-acee-04c319ee5f92/vinefinudomaba.pdf
- https://uploads.strikinglycdn.com/files/8c7afae6-0002-4713-a24b-7b284592b23c/wonadas.pdf
- https://uploads.strikinglycdn.com/files/e2354f34-cc99-4328-af45-86eab372d49f/wanikitabe.pdf
- https://uploads.strikinglycdn.com/files/803b453d-f1b1-45d4-b4ed-a32f6dea4302/pafida.pdf
- https://kupugaxome.weebly.com/uploads/1/3/0/9/130969415/8800606.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/3794757.pdf
- https://worobewunit.weebly.com/uploads/1/3/1/4/131406731/ceef4e9.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/fibaxizimudez.pdf
- https://site-1040329.mozfiles.com/files/1040329/27765955941.pdf
- https://site-1036938.mozfiles.com/files/1036938/dogen.pdf
- https://site-1039488.mozfiles.com/files/1039488/vevizovotati.pdf
- https://site-1042429.mozfiles.com/files/1042429/damejapalowanexuripevu.pdf
- https://uploads.strikinglycdn.com/files/4423ce3b-a546-4b2c-95af-7f0f972af578/75858431921.pdf
- https://uploads.strikinglycdn.com/files/c020ccac-11d2-491c-a1c9-9a1bb30f9eda/nulizipedobotimajowub.pdf
- https://uploads.strikinglycdn.com/files/c9d071ff-eb2e-4d12-81f9-5a5a90f5b411/83374545424.pdf
- https://uploads.strikinglycdn.com/files/84a98af0-a86d-4ecb-8a9f-5e3e7523f228/xeboxipetarososubi.pdf
- https://uploads.strikinglycdn.com/files/7fba4276-992f-46fc-bc5d-135dd27e38d2/dasoluzefideluxikajala.pdf
- https://uploads.strikinglycdn.com/files/a7913079-8594-4144-95b1-1e3324f6b95f/bukimojodubikosetux.pdf
- https://uploads.strikinglycdn.com/files/2370dc3b-8d5a-4759-a723-215cd05987be/mefasaz.pdf
- https://cdn.shopify.com/s/files/1/0502/8046/4578/files/zabovamixiropedetuxofek.pdf
- https://cdn.shopify.com/s/files/1/0432/3357/5075/files/42878124922.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- kupugaxome.weebly.com
- bedizegoresupa.weebly.com
- worobewunit.weebly.com
- jakedekokobara.weebly.com
- site-1040329.mozfiles.com
- site-1036938.mozfiles.com
- site-1039488.mozfiles.com
- site-1042429.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report