Malicious PDF — malware analysis report

Static analysis result for SHA-256 2af7dc8ed9f8c80e…

MALICIOUS

PDF

17.9 KB Created: 2019-05-01 19:18:02 +01:00 Authoring application: mPDF 5.7 First seen: 2021-07-10
MD5: 3aae0b1ca426aeede7f6493add9fcf5d SHA-1: 2655a944e3570ce844465bdf7707c16695793abe SHA-256: 2af7dc8ed9f8c80eba76ba550f9bd57a3e67a89c32cee72e88cd5a35f5bd61ac
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, forming a link farm. The ML classifier strongly indicated maliciousness, and the PDF structure suggests an attempt to drive traffic to a collection of poetry anthologies. While the URLs themselves are marked as benign, the sheer volume and structure of the links within the PDF indicate a malicious intent, likely to distribute or monetize traffic to these external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4095099098099094/The-Ring-Of-Words-An-Anthology-Of-Poetry-For-Children-by-Roger-McGough.pdf In PDF document text
    • http://loaminoo.linkpc.net/4095099097094097/All-the-Best-The-Selected-Poems-Of-Roger-Mc-Gough-by-Roger-McGough.pdfIn PDF document text
    • http://loaminoo.linkpc.net/8094091091092093/A-Rain-of-Words-A-Bilingual-Anthology-of-Women-s-Poetry-in-Francophone-Africa-by-Ir-ne-Assiba-d-39-Almeida.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4095099091094097/In-the-Glassroom-by-Roger-McGough.pdfIn PDF document text
    • http://loaminoo.linkpc.net/5092097096094092/The-Kingfisher-Book-of-Funny-Poems-by-Roger-McGough.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1098093092097/No-Sign-of-Ceasefire-An-Anthology-of-Contemporary-Israeli-Poetry-An-Anthology-of-Contemporary-Israeli-Poetry-by-Warren-Bargad.pdfIn PDF document text
    • http://loaminoo.linkpc.net/9092095093093093/My-poetry-depicts-you-An-anthology-of-contemporary-Kurdish-poetry-by-Rebwar-Fatah.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4099095095095090/A-Boom-in-the-Room-an-Anthology-of-Student-Poetry-Student-Poetry-Anthologies-Book-1-by-Annie-Douglass-Lima.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2091090094090091/A-Familiar-Ring-by-Roger-Terry.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4095099092095097/An-Anthology-of-Modern-Irish-Poetry-by-Wes-Davis.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4095099093093096/The-Seashell-Anthology-of-Great-Poetry-by-Christopher-Burns.pdfIn PDF document text
    • http://loaminoo.linkpc.net/8090090092095094/Confucius-to-Cummings-An-Anthology-of-Poetry-by-Ezra-Pound.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2096095090095096/Classical-Chinese-Poetry-An-Anthology-by-David-Hinton.pdfIn PDF document text
    • http://loaminoo.linkpc.net/6093091095095/An-Anthology-of-New-Zealand-Poetry-in-English-by-Jenny-Bornholdt.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4093090090096097/Poetry-After-9-11-An-Anthology-of-New-York-Poets-by-Dennis-Loy-Johnson.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1093098097092091/From-the-Country-of-Eight-Islands-An-Anthology-of-Japanese-Poetry-by-Hiroaki-Sato.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2097091096097094/My-Cruel-Invention-A-Contemporary-Poetry-Anthology-by-Bernadette-Geyer.pdfIn PDF document text
    • http://loaminoo.linkpc.net/6090095094091094/Modern-Arabic-Poetry-An-Anthology-by-Salma-Khadra-Jayyusi.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1090096098099096099/An-Anthology-of-German-Poetry-from-Holderlin-to-Rilke-by-ngel-Flores.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2091094093095/Children-of-War-by-Roger-Rosenblatt.pdfIn PDF document text