Malicious PDF — malware analysis report

Static analysis result for SHA-256 b23152e17258ddd1…

MALICIOUS

PDF

23.2 KB Created: 2019-05-06 16:54:59 +01:00 Authoring application: mPDF 5.7
MD5: 7703384bf497f096ae82c40921b7ef83 SHA-1: 77b939cec4b49fd82098536dba579cea3e4920b1 SHA-256: b23152e17258ddd128a8bb075e4a26c31ad2650bd8f44af9ec069f4c3aa5ba67
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was identified as malicious due to a critical heuristic firing for a PDF link farm. It contains numerous embedded URLs, with the primary one being http://loaminoo.linkpc.net/7091098098095095/Past-Life-Regression-Remember-Past-Lives-and-Reincarnation-with-Hypnosis-via-Beach-Hypnosis-and-Meditation-by-Gelina-Ray.pdf. While the document body is unreadable, the structure and the link farm heuristic strongly suggest a malicious intent, possibly related to SEO manipulation or hosting further malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7091098098095095/Past-Life-Regression-Remember-Past-Lives-and-Reincarnation-with-Hypnosis-via-Beach-Hypnosis-and-Meditation-by-Gelina-Ray.pdf
    • http://loaminoo.linkpc.net/7091098098094096/Past-Life-Regression-Remember-Past-Lives-and-Reincarnation-with-Hypnosis-by-Gelina-Ray.pdf
    • http://loaminoo.linkpc.net/7091098098094095/Astral-Projection-Learn-How-to-Astral-Project-with-Beach-Hypnosis-and-Meditation-by-Gelina-Ray.pdf
    • http://loaminoo.linkpc.net/1091091093098091093/Untying-the-Karmic-Knot-Healing-Through-Past-Life-Regression-Therapy-Knowledge-Through-Life-Between-Lives-Therapy-the-Earth-s-Future-Through-by-Diane-Morrin.pdf
    • http://loaminoo.linkpc.net/1098093098099090/Past-Lives-1-Rachel-Past-Lives-1-by-Stephanie-Abbott.pdf
    • http://loaminoo.linkpc.net/9092097098092099/Many-Lives-Many-Masters-The-True-Story-of-a-Prominent-Psychiatrist-His-Young-Patient-and-the-Past-Life-Therapy-That-Changed-Both-Their-Lives-by-Brian-L-Weiss.pdf
    • http://loaminoo.linkpc.net/1090096090096099098/Hypno-Health-How-to-Transform-Your-Life-Through-the-Power-of-Self-Hypnosis-by-Robert-Farago.pdf
    • http://loaminoo.linkpc.net/5099099097098090/The-Everything-Guide-to-Past-Life-Experiences-Explore-the-Scientific-Spiritual-and-Philosophical-Evidence-of-Past-Life-Experiences-by-Jock-Brocas.pdf
    • http://loaminoo.linkpc.net/4095095095094098/Have-You-Lived-Before-This-Life-A-Scientific-Survey-A-Study-Of-Past-Lives-Through-Dianetic-Engrams-by-L-Ron-Hubbard.pdf
    • http://loaminoo.linkpc.net/3091098098090098/Releasing-You-From-The-Past-Healing-Past-Hurt-Through-Forgiveness-by-Stephen-Richards.pdf
    • http://loaminoo.linkpc.net/8093092093091092/A-Practical-Guide-to-Self-Hypnosis-by-Melvin-Powers.pdf
    • http://loaminoo.linkpc.net/9095094098093090/Handbook-of-Clinical-Hypnosis-by-Judith-W-Rhue.pdf
    • http://loaminoo.linkpc.net/8097098094093091/Integrative-Hypnosis-A-Comprehensive-Course-in-Change-by-Melissa-Tiers.pdf
    • http://loaminoo.linkpc.net/6093099093099099/Lives-of-Future-Past-by-S-K-Benton.pdf
    • http://loaminoo.linkpc.net/1091097098091096/Past-Lives-by-Christopher-Kokoski.pdf
    • http://loaminoo.linkpc.net/6097092090098095/Hypnosis-and-Behaviour-Modification-Imagery-Conditioning-by-William-S-Kroger.pdf
    • http://loaminoo.linkpc.net/4091092095097091/Bioplasticity-Hypnosis-Mind-Body-Healing-by-Joseph-Sansone.pdf
    • http://loaminoo.linkpc.net/2092093091093094/Past-Lives-Future-Healing-by-Sylvia-Browne.pdf
    • http://loaminoo.linkpc.net/3099095093092095/Followng-The-Drum-The-Lives-of-Army-Wives-and-Daughters-Past-and-Present-by-Annabel-Venning.pdf
    • http://loaminoo.linkpc.net/6095094095098091/My-Mystical-Past-Life-by-Venu-Murthy-M-K-.pdf
    • http://loaminoo.linkpc.net/1091091093098091093/Untying-the-Karmic-Knot-Healing-Through-Past-Life-Regression-Therapy-Knowledge-Through-Life-Between-Lives-Therapy-the-Earth-s-Future-Through-by-Dia