Malicious PDF — malware analysis report

Static analysis result for SHA-256 22df6cbfab874f1f…

MALICIOUS

PDF

14.5 KB Created: 2019-05-01 17:57:22 +01:00 Authoring application: mPDF 5.7
MD5: 8c423fbc8825c745e1165fb5e25ad9be SHA-1: 12343950b5a5b67fcbbbe4b7c3dac4ce596352c8 SHA-256: 22df6cbfab874f1fa17c6419dd9ff6b696111dd48df3ee5fb74cbbe4a4c7c4df
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links point to various book titles hosted on the `xiixmcuin.linkpc.net` domain. While the individual URLs are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO spam or to distribute further payloads. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1202206202204206/Exile-The-Extinction-Trials-2-by-S-M-Wilson.pdf
    • http://xiixmcuin.linkpc.net/3203200203206208/The-Extinction-Trials-by-S-M-Wilson.pdf
    • http://xiixmcuin.linkpc.net/9208206208/Extinction-Horizon-The-Extinction-Cycle-1-by-Nicholas-Sansbury-Smith.pdf
    • http://xiixmcuin.linkpc.net/1205205209200206/Extinction-Edge-The-Extinction-Cycle-2-by-Nicholas-Sansbury-Smith.pdf
    • http://xiixmcuin.linkpc.net/1205205209202203/Extinction-Evolution-The-Extinction-Cycle-4-by-Nicholas-Sansbury-Smith.pdf
    • http://xiixmcuin.linkpc.net/1205205209204208/Extinction-Lost-The-Extinction-Cycle-6-5-by-Nicholas-Sansbury-Smith.pdf
    • http://xiixmcuin.linkpc.net/1205205209203207/Extinction-Aftermath-The-Extinction-Cycle-6-by-Nicholas-Sansbury-Smith.pdf
    • http://xiixmcuin.linkpc.net/1205205209201206/Extinction-Age-The-Extinction-Cycle-3-by-Nicholas-Sansbury-Smith.pdf
    • http://xiixmcuin.linkpc.net/9207209200/Extinction-End-The-Extinction-Cycle-5-by-Nicholas-Sansbury-Smith.pdf
    • http://xiixmcuin.linkpc.net/8204202202202209/Salem-Witch-Trials-The-True-Story-Behind-The-Infamous-Witch-Trials-of-1692-by-Anna-Revell.pdf
    • http://xiixmcuin.linkpc.net/2209204202205203/The-Angel-Trials-Dark-World-The-Angel-Trials-1-by-Michelle-Madow.pdf
    • http://xiixmcuin.linkpc.net/3203205201201209/Famous-Trials-Oscar-Wilde-Famous-Trials-7-by-H-Montgomery-Hyde.pdf
    • http://xiixmcuin.linkpc.net/1208200202205203/Exile-Exile-1-by-Kevin-Emerson.pdf
    • http://xiixmcuin.linkpc.net/1201209208200200/Queen-in-Exile-Queen-in-Exile-1-by-Oliver-Strong.pdf
    • http://xiixmcuin.linkpc.net/5200200209202207/The-Yankee-Problem-An-American-Dilemma-The-Wilson-Files-Book-1-by-Clyde-N-Wilson.pdf
    • http://xiixmcuin.linkpc.net/3207205204207209/The-Love-Trials-2-The-Love-Trials-2-by-J-S-Cooper.pdf
    • http://xiixmcuin.linkpc.net/1207204206206208/The-Love-Trials-3-The-Love-Trials-3-by-J-S-Cooper.pdf
    • http://xiixmcuin.linkpc.net/3207205207207209/The-Love-Trials-1-The-Love-Trials-1-by-J-S-Cooper.pdf
    • http://xiixmcuin.linkpc.net/3209205207204205/The-Love-Trials-1-The-Love-Trials-1-by-J-S-Cooper.pdf
    • http://xiixmcuin.linkpc.net/4209204204206205/Edward-Wilson-s-Nature-Notebooks-by-David-M-Wilson.pdf
    • http://xiixmcuin.linkpc.net/9207209200/Extinction-End-The-Extinction-Cycle-5-by-Nicholas-