Malicious PDF — malware analysis report

Static analysis result for SHA-256 a5826f4361933ebe…

MALICIOUS

PDF

17.5 KB Created: 2019-04-30 01:57:12 +01:00 Authoring application: mPDF 5.7
MD5: 6a32fa4144cb9325f74d1f8f214b9095 SHA-1: ae225517d39a39ebfc5c3f04d2fa7f3c9334c174 SHA-256: a5826f4361933ebe23be036ea917b85ab5025282b5dfdcc1b4537524f72380ef
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. The document body, though partially corrupted, contains these URLs, suggesting a tactic to drive traffic to these external resources. The purpose appears to be SEO manipulation or a form of link-based spam, rather than direct malware delivery.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8090097099097/Getting-Into-Poetry-A-Readers-and-Writers-Guide-to-the-Poetry-Scene-by-Paul-Hyland.pdf
    • http://loaminoo.linkpc.net/6096093094092098/Poetry-in-Composition-A-Coffee-Table-Book-of-Poetry-and-Photos-by-Angel-Leya.pdf
    • http://loaminoo.linkpc.net/9092095093093093/My-poetry-depicts-you-An-anthology-of-contemporary-Kurdish-poetry-by-Rebwar-Fatah.pdf
    • http://loaminoo.linkpc.net/4090091096092098/Poetry-Changes-Lives-Daily-Thoughts-on-Poetry-and-History-by-Christopher-Burn.pdf
    • http://loaminoo.linkpc.net/4095099093093093/Partial-Eclipse-A-Book-of-Poetry-Vassar-Miller-Prize-in-Poetry-1-by-Tony-Sanders.pdf
    • http://loaminoo.linkpc.net/1098092097098098/Poetry-180-A-Turning-Back-to-Poetry-by-Billy-Collins.pdf
    • http://loaminoo.linkpc.net/4099095095095090/A-Boom-in-the-Room-an-Anthology-of-Student-Poetry-Student-Poetry-Anthologies-Book-1-by-Annie-Douglass-Lima.pdf
    • http://loaminoo.linkpc.net/9091098091099097/The-Faber-Book-of-Contemporary-Irish-Poetry-by-Paul-Muldoon.pdf
    • http://loaminoo.linkpc.net/1096099092095098/Beautiful-and-Pointless-A-Guide-to-Modern-Poetry-by-David-Orr.pdf
    • http://loaminoo.linkpc.net/8097090092099092/The-Random-House-Book-of-20th-Century-French-Poetry-by-Paul-Auster.pdf
    • http://loaminoo.linkpc.net/9098098092094099/The-Discourse-of-Nature-in-the-Poetry-of-Paul-Celan-The-Unnatural-World-by-Rochelle-Tobias.pdf
    • http://loaminoo.linkpc.net/1090094090099098/The-Poet-s-Companion-A-Guide-to-the-Pleasures-of-Writing-Poetry-by-Kim-Addonizio.pdf
    • http://loaminoo.linkpc.net/3099093091092093/The-Discovery-of-Poetry-A-Field-Guide-to-Reading-and-Writing-Poems-by-Frances-Mayes.pdf
    • http://loaminoo.linkpc.net/7092092093093099/The-Sound-of-Poetry-The-Poetry-of-Sound-by-Perloff-Marjorie.pdf
    • http://loaminoo.linkpc.net/1098093092097/No-Sign-of-Ceasefire-An-Anthology-of-Contemporary-Israeli-Poetry-An-Anthology-of-Contemporary-Israeli-Poetry-by-Warren-Bargad.pdf
    • http://loaminoo.linkpc.net/6095099097092099/The-Collected-Poetry-of-Paul-Laurence-Dunbar-by-Paul-Laurence-Dunbar.pdf
    • http://loaminoo.linkpc.net/4095099096097095/The-New-Poetry-by-Al-lvarez.pdf
    • http://loaminoo.linkpc.net/4098093098097094/Shadows-of-Poetry-by-A-F-Stewart.pdf
    • http://loaminoo.linkpc.net/6095095095092098/Nearly-Too-Much-The-Poetry-of-J-H-Prynne-by-N-H-Reeve.pdf
    • http://loaminoo.linkpc.net/4090098098097096/Tears-of-Poetry-by-A-F-Stewart.pdf
    • http://loaminoo.linkpc.net/9091098091099097/The-Faber-Book-of-C