SUSPICIOUS — mefalod.pdf
SUSPICIOUS — mefalod.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4ac835fde6d2c177a78ae33e4a4b8948a8528269cca485390a78660a8524fee3 - SHA-1:
7d57e1be9673f398e8de295185205a7aa8bc660e - MD5:
cc123f4dbc75b2595d06675a7edd730f - ssdeep:
768:GgGzpDIpQwD8kxqvoPTfCtOJ65Al7E0cHS8tTacPnn5S5RR5b:TGFspx8oqg7fCcJHj8tTBPnn5S5RR5b - TLSH:
T19632A0F351BBDE8C7EC7AB43ADA7155460499388723793A06498772CC0B82BD7F119A0 - Submitted as: mefalod.pdf
- File type: pdf · Size: 44582 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/6085e43e-179a-4055-8dbb-f15ce454dd6c/78557688264.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=mortalit%25C3%25A9+n%25C3%25A9onatale+en+afrique+pdf, https://uploads.strikinglycdn.com/files/6085e43e-179a-4055-8dbb-f15ce454dd6c/78557688264.pdf, https://uploads.strikinglycdn.com/files/68b32fbf-8d49-4f77-a6d1-ae79c26b25c7/10557822677.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=mortalit%25C3%25A9+n%25C3%25A9onatale+en+afrique+pdf
- https://uploads.strikinglycdn.com/files/6085e43e-179a-4055-8dbb-f15ce454dd6c/78557688264.pdf
- https://uploads.strikinglycdn.com/files/68b32fbf-8d49-4f77-a6d1-ae79c26b25c7/10557822677.pdf
- https://uploads.strikinglycdn.com/files/0755b5cb-d039-47d5-a2db-715a36e01cb4/wilodijoxobedi.pdf
- https://uploads.strikinglycdn.com/files/eeb8764f-8687-4f0d-8c7d-a9b671c62b83/linude.pdf
- https://uploads.strikinglycdn.com/files/42172604-f18a-4baa-88b9-840f31178ea3/lugubadawabatov.pdf
- https://uploads.strikinglycdn.com/files/77825902-0c94-4404-ab99-5d8b308085ce/36073753612.pdf
- https://uploads.strikinglycdn.com/files/eb2b4133-3dcf-49cd-b423-ad04cddb10c2/viramuzufos.pdf
- https://uploads.strikinglycdn.com/files/7106896f-8eba-40fa-b52c-9d0bbe012014/xumusefasitagoleteg.pdf
- https://uploads.strikinglycdn.com/files/2ecf6f91-b43d-4921-b17a-516a4c25225d/14619107468.pdf
- https://uploads.strikinglycdn.com/files/be5f00d6-eb7d-4e5c-a55f-f3555813cafd/wetaxorotapigibanu.pdf
- https://uploads.strikinglycdn.com/files/80eddb07-e8a2-45cc-a1ad-58e2b080d539/96003013252.pdf
- https://uploads.strikinglycdn.com/files/2cac6de6-0a07-41c2-8151-4e012c1c223e/kuwerugifuvavi.pdf
- https://uploads.strikinglycdn.com/files/7c36b679-dc6d-42cd-a3a4-6ce4f6996324/pibusumufaro.pdf
- https://uploads.strikinglycdn.com/files/2ce756e0-9f64-4e5e-a2e2-f35da85ddc80/72630178723.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report