Malicious PDF — malware analysis report

Static analysis result for SHA-256 22f16b4fb26c0d2a…

MALICIOUS

PDF

18.7 KB Created: 2019-04-30 04:33:04 +01:00 Authoring application: mPDF 5.7 First seen: 2021-05-29
MD5: 99f32909967163720f6ca5a5c5f07da6 SHA-1: 6d620c4fd518c104e955ad3be74dfe20494de08f SHA-256: 22f16b4fb26c0d2a79a4af5695a5281b32b9076803d70ff211473430cf0f429b
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external websites, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these URLs are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/3208200202203203/Double-Feature-Timber-Ridge-Riders-9-by-Maggie-Dana.pdf In PDF document text
    • http://xiixmcuin.linkpc.net/4206206200205200/Racing-into-Trouble-Timber-Ridge-Riders-2-by-Maggie-Dana.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/8204206207206/Timber-Ridge-Reflections-Timber-Ridge-Reflections-1-3-by-Tamera-Alexander.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/3205209200207208/Deadly-Double-Florida-Mystery-Double-Feature-2-by-Diane-Capri.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/2200201205207/Beyond-This-Moment-Timber-Ridge-Reflections-2-by-Tamera-Alexander.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/3209207200209200/Cobalt-City-Double-Feature-by-Erik-Scott-de-Bie.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/4205201209204203/A-Night-at-the-Operation-Double-Feature-Mystery-3-by-Jeffrey-Cohen.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/3205209203206200/Florida-Is-Murder-Due-Justice-and-Surface-Tension-Mystery-Double-Feature-by-Diane-Capri.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/3203204209205203/Racing-for-the-Stars-Best-Friends-3-by-Maggie-Dana.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/3208202208201202/Song-of-Midnight-Embers-Maggie-s-Grove-4-by-Dana-Marie-Bell.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/1209200206201/Double-Feature-Attack-of-the-Soul-Sucking-Brain-Zombies-Bride-of-the-Soul-Sucking-Brain-Zombies-Russel-Middlebrook-3-by-Brent-Hartinger.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/2200208206204201/The-Rocky-Ridge-Collection-Little-House-on-Rocky-Ridge-Little-Farm-in-the-Ozarks-in-the-Land-of-the-Big-Red-Apple-on-the-Other-Side-of-the-Hill-Little-House-The-Rocky-Ridge-Years-1-4-by-Roger-Lea-MacBride.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/1200203209209206208/Double-Double-How-to-Double-Your-Revenue-amp-Profit-in-3-Years-or-Less-by-Cameron-Herold.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/7204209204202201/Bitch-Planet-Triple-Feature-Vol-1-Bitch-Planet-Triple-Feature-1-by-Kelly-Sue-DeConnick.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/2206201209/Riders-Riders-1-by-Veronica-Rossi.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/1200209206201208201/Summer-at-Mustang-Ridge-Mustang-Ridge-1-by-Jesse-Hayworth.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/2202205200204209/Winter-at-Mustang-Ridge-Mustang-Ridge-2-by-Jesse-Hayworth.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/4203204205202201/Cold-Ridge-Cold-Ridge-U-S-Marshals-1-by-Carla-Neggers.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/9206204207201208/Butch-Fatale-Dyke-Dick---Double-D-Double-Cross-by-Christa-Faust.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/1201206205202202/Double-Threats-Forever-Double-Threat-4-by-Julie-Prestsater.pdfIn PDF document text