Malicious PDF — malware analysis report

Static analysis result for SHA-256 96d3d92c434f68d7…

MALICIOUS

PDF

17.1 KB Created: 2019-05-02 17:57:54 +01:00 Authoring application: mPDF 5.7
MD5: 76f043fac84b406cb2eb95e130d01aa9 SHA-1: b527a7b53a4c470ece70503578d7ad4c468cf443 SHA-256: 96d3d92c434f68d73792f6a7095086c187391f437f09a82503ab819d2c40ec2e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links point to external websites, suggesting a phishing or social engineering attempt to direct users to malicious content. While the URLs themselves are currently marked as benign, the sheer volume and nature of the links indicate a deliberate attempt to manipulate user interaction. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7092091099092/Reconnecting-with-Nature-Finding-Wellness-Through-Rebuilding-Your-Bond-with-the-Earth-by-Michael-J-Cohen.pdf
    • http://loaminoo.linkpc.net/2092091094090/The-Sky-and-Earth-Touched-Me-Sharing-Nature-Wellness-Exercises-by-Joseph-Bharat-Cornell.pdf
    • http://loaminoo.linkpc.net/3098095093095090/The-Earth-is-Good-A-Chant-in-Praise-of-Nature-by-Michael-DeMunn.pdf
    • http://loaminoo.linkpc.net/1091095092096095098/EcoCities-Rebuilding-Cities-in-Balance-with-Nature-by-Richard-Register.pdf
    • http://loaminoo.linkpc.net/4099094097096092/Talking-with-Nature-and-Journey-into-Nature-by-Michael-J-Roads.pdf
    • http://loaminoo.linkpc.net/5090097097091098/Our-Modern-Times-The-Nature-of-Capitalism-in-the-Information-Age-by-Daniel-Cohen.pdf
    • http://loaminoo.linkpc.net/7099098093097097/HUMUS-the-black-gold-of-the-earth-by-Veronika-Bond.pdf
    • http://loaminoo.linkpc.net/2098092098097095/Zen-in-the-Garden-Finding-Peace-and-Healing-Through-Nature-by-Tracy-J-Thomas.pdf
    • http://loaminoo.linkpc.net/1091096097095092/Mysterious-Patterns-Finding-Fractals-in-Nature-by-Sarah-C-Campbell.pdf
    • http://loaminoo.linkpc.net/5091098090092095/Finding-Oil-The-Nature-of-Petroleum-Geology-1859-1920-by-Brian-Frehner.pdf
    • http://loaminoo.linkpc.net/1092091095096094/Gilean-Douglas-Writing-Nature-Finding-Home-by-Andrea-Pinto-Lebowitz.pdf
    • http://loaminoo.linkpc.net/4092098098092097/The-Healing-Wisdom-of-Africa-Finding-Life-Purpose-Through-Nature-Ritual-and-Community-by-Malidoma-Patrice-Som-.pdf
    • http://loaminoo.linkpc.net/1090092098098099098/Paddington-at-the-Palace-by-Michael-Bond.pdf
    • http://loaminoo.linkpc.net/1093098094098098/The-Adventures-of-Paddington-by-Michael-Bond.pdf
    • http://loaminoo.linkpc.net/1090092098099090092/Paddington-at-the-Beach-by-Michael-Bond.pdf
    • http://loaminoo.linkpc.net/1090092098099094097/Paddington-Minds-the-House-by-Michael-Bond.pdf
    • http://loaminoo.linkpc.net/6092090099098096/Monsieur-Pamplemousse-Aloft-by-Michael-Bond.pdf
    • http://loaminoo.linkpc.net/6092090098095092/Monsieur-Pamplemousse-on-the-Spot-by-Michael-Bond.pdf
    • http://loaminoo.linkpc.net/2095091094094096/A-Bear-Called-Paddington-by-Michael-Bond.pdf
    • http://loaminoo.linkpc.net/6092091090090091/Monsieur-Pamplemousse-Takes-the-Train-by-Michael-Bond.pdf
    • http://loaminoo.linkpc.net/2098092098097095/Zen-in-the-Ga