Malicious PDF — malware analysis report

Static analysis result for SHA-256 7194e70ee21a2115…

MALICIOUS

PDF

26.0 KB Created: 2019-05-07 04:19:23 +01:00 Authoring application: mPDF 5.7
MD5: b22c177b8571f4f3867d4ab441cb8e47 SHA-1: d03091eab7bcf44beac76840acfe1f52f3a94363 SHA-256: 7194e70ee21a21159ab1a04d03c6f5b4a87aa23287435d551bbc390deb4fb945
132 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF sample contains a critical heuristic firing for a mass external PDF link farm, indicating a potential SEO poisoning or spamming campaign. Additionally, a high severity heuristic for 'eval() call' within a decoded stream suggests the execution of arbitrary JavaScript code. The ML classifier also flagged the PDF as malicious with high confidence. These factors point to an attempt to exploit the PDF viewer to download and execute further payloads from the listed URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9716

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/7a00a00a08a08a09/Le-Chasseur-an-Chien-d-Arr-t-Contenant-Les-Habitudes-Les-Ruses-Du-Gibier-l-Art-de-Le-Chercher-Et-de-Le-Tirer-Le-Choix-Des-Armes-l-ducation-Des-Chiens-Leurs-Maladies-Etc-by-Elz-ar-Blaze.pdf
    • http://muicuiu.dumb1.com/7a00a00a08a08a08/Le-Chasseur-an-Chien-d-Arr-t-Contenant-Les-Habitudes-Les-Ruses-Du-Gibier-l-Art-de-Le-Chercher-Et-de-Le-Tirer-Le-Choix-Des-Armes-l-ducation-Des-Chiens-Leurs-Maladies-Etc-by-Elz-ar-Blaze.pdf
    • http://muicuiu.dumb1.com/4a04a09a09a02a00/Kingdom-of-Ruses-Ruses-1-by-Kate-Stradling.pdf
    • http://muicuiu.dumb1.com/5a07a00a08a05a02/-liminer-les-Habitudes-N-gatives-Les-m-thodes-qui-vous-aideront-d-truire-facilement-les-mauvaises-habitudes-Acqu-rir-l-Unit-formation-professionnelle-personnel-t-17-by-Mohammed-Mouhssine.pdf
    • http://muicuiu.dumb1.com/7a07a03a09a08a03/ARR-TER-VOTRE-CHIEN-DE-MANGER-POO-D-couvrir-Exactement-Pourquoi-Votre-Chien-Mange-Crotte-Et-Comment-Rapidement-Et-Facilement-Mettre-Un-Terme-Ce-Comportement-Easy-Pet-Care-S-rie-t-3-by-Mark-Hamilton.pdf
    • http://muicuiu.dumb1.com/6a07a08a07a07a09/L-Ame-du-chasseur-by-Deon-Meyer.pdf
    • http://muicuiu.dumb1.com/2a03a00a05a00/Interpreter-of-Maladies-by-Jhumpa-Lahiri.pdf
    • http://muicuiu.dumb1.com/5a06a02a02a08a09/Le-choix-des-Morrison-by-Mary-Lawson.pdf
    • http://muicuiu.dumb1.com/5a07a08a07a03a04/Chasseur-Cheval-Napoleonic-Horseman-1-by-Griff-Hosker.pdf
    • http://muicuiu.dumb1.com/6a09a03a08a05a03/L-art-de-poser-humblement-les-questions-Comment-tirer-profit-d-une-communication-efficace-by-Edgar-H-Schein.pdf
    • http://muicuiu.dumb1.com/6a07a08a06a00a06/Les-Chiens-de-Riga-by-Henning-Mankell.pdf
    • http://muicuiu.dumb1.com/6a02a00a08a01a07/Les-chiens-de-brouillard-by-Stephane-Gravier.pdf
    • http://muicuiu.dumb1.com/6a06a00a04a06a00/The-Histamine-H3-Receptor-A-Target-for-New-Drugs-by-Rob-Leurs.pdf
    • http://muicuiu.dumb1.com/5a05a08a05a01a03/Les-Chiens-du-rideau-de-fer-by-Marie-Luise-Scherer.pdf
    • http://muicuiu.dumb1.com/7a00a00a06a09a01/Viens-me-chercher-by-Catherine-Mann.pdf
    • http://muicuiu.dumb1.com/7a00a00a06a08a06/Fallait-pas-me-chercher---6-by-Emma-M-Green.pdf
    • http://muicuiu.dumb1.com/7a00a00a07a06a07/Et-si-je-revenais-te-chercher-by-BeeBen-e-Books.pdf
    • http://muicuiu.dumb1.com/4a04a07a03a01a07/Royal-Maladies-Inherited-Diseases-in-the-Ruling-Houses-of-Europe-by-Alan-R-Rushton.pdf
    • http://muicuiu.dumb1.com/8a00a09a07a05a09/Third-World-Film-Making-and-the-West-by-Roy-Armes.pdf
    • http://muicuiu.dumb1.com/7a00a00a08a02a02/Mon-fils-va-venir-me-chercher-by-Patrick-Breuz-.pdf