Malicious PDF — malware analysis report

Static analysis result for SHA-256 f03d4a9a64357299…

MALICIOUS

PDF

21.6 KB Created: 2019-04-30 08:08:16 +01:00 Authoring application: mPDF 5.7
MD5: 3b9acc536f39d3ec30a2b17218885d84 SHA-1: 7b453dfc35edca811c97a006f0409bb250f28969 SHA-256: f03d4a9a6435729922d072b4f1d7a2ea6e2e35b4dcfefa6fe8b75da5723d7022
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of external links, identified as a link farm. The primary heuristic indicates this is a critical finding, suggesting a malicious intent to redirect users to potentially harmful content. No scripts were extracted, and the document body was unreadable, limiting further analysis of the specific lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4092093095098097/In-God-s-Name-An-Investigation-into-the-Murder-of-Pope-John-Paul-I-by-David-A-Yallop.pdf
    • http://loaminoo.linkpc.net/6096093096094095/Le-pape-doit-mourir-enqu-te-sur-la-mort-suspecte-de-Jean-Paul-1er-by-David-A-Yallop.pdf
    • http://loaminoo.linkpc.net/7092091099091093/Pope-John-Paul-IIs-Theological-Journey-to-the-Prayer-Meeting-of-Religions-in-Assisi-Part-2-3-by-Johannes-D-rmann.pdf
    • http://loaminoo.linkpc.net/7095092094099097/The-First-and-Second-Missionary-Journey-of-Pope-John-Paul-II-to-Nigeria-The-Beatification-of-Father-Cyprian-Michael-Iwene-Tansi-March-22-1998-by-S-Iniobong-Udoidem.pdf
    • http://loaminoo.linkpc.net/4095095097098097/Mounting-Evidence-Why-We-Need-a-New-Investigation-Into-9-11-by-Paul-W-Rea.pdf
    • http://loaminoo.linkpc.net/4094092090092092/Escapo-by-Paul-Pope.pdf
    • http://loaminoo.linkpc.net/2093098097096/Batman-Year-100-by-Paul-Pope.pdf
    • http://loaminoo.linkpc.net/5098096097099092/Thanksgiving-An-Investigation-of-a-Pauline-Theme-by-David-W-Pao.pdf
    • http://loaminoo.linkpc.net/4094097090095092/Unsolved-Mysteries-of-History-An-Eye-Opening-Investigation-Into-the-Most-Baffling-Events-of-All-Time-by-Paul-Aron.pdf
    • http://loaminoo.linkpc.net/6094095095095/Pope-Francis-Untying-the-Knots-by-Paul-Vallely.pdf
    • http://loaminoo.linkpc.net/2096096095094097/Catastrophe-An-Investigation-into-the-Origins-of-Modern-Civilization-by-David-Keys.pdf
    • http://loaminoo.linkpc.net/2097099092094093/The-Pope-Who-Would-Be-King-The-Exile-of-Pius-IX-and-the-Emergence-of-Modern-Europe-by-David-I-Kertzer.pdf
    • http://loaminoo.linkpc.net/1091093098092092091/All-the-Pope-s-Saints-The-Jesuits-Who-Shaped-Pope-Francis-by-Sean-Salai.pdf
    • http://loaminoo.linkpc.net/4093094097092091/Pope-Pourri-What-You-Don-t-Remember-From-Catholic-School-by-John-Dollison.pdf
    • http://loaminoo.linkpc.net/7091097098096096/Pope-John-XXIII-Essential-Writings-by-Jean-Maalouf.pdf
    • http://loaminoo.linkpc.net/3096092096095098/Hitler-s-Pope-The-Secret-History-of-Pius-XII-by-John-Cornwell.pdf
    • http://loaminoo.linkpc.net/6097093097095/The-Underground-History-of-American-Education-An-Intimate-Investigation-Into-the-Prison-of-Modern-Schooling-by-John-Taylor-Gatto.pdf
    • http://loaminoo.linkpc.net/3096092096097098/Light-of-the-World-The-Pope-the-Church-and-the-Signs-of-the-Times---A-Conversation-with-Peter-Seewald-by-Pope-Benedict-XVI.pdf
    • http://loaminoo.linkpc.net/4095094098098090/Murder-Most-Gay-Murder-Most-Gay-1-by-John-Simpson.pdf
    • http://loaminoo.linkpc.net/9092091090092093/True-or-False-Pope-Refuting-Sedevacantism-and-Other-Modern-Errors-by-John-Salza.pdf