Malicious PDF — malware analysis report

Static analysis result for SHA-256 1ae50e391e13378b…

MALICIOUS

PDF

19.2 KB Created: 2019-04-30 02:46:57 +01:00 Authoring application: mPDF 5.7
MD5: 5a7c34a8ba46d43b396ffe71495a6d02 SHA-1: 1b731d3143af1960ad489c6a4286a8e5b588e1b1 SHA-256: 1ae50e391e13378bd1d1bfd8f1507acea3ea8d4558685693bb367e27e24faa8a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily corrupted, the presence of numerous links suggests an attempt to manipulate search engine results or distribute content from a specific domain. The primary IOC is the domain loaminoo.linkpc.net, which hosts a large number of these linked PDFs.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3090093094093097/Electric-Best-Lesbian-Erotic-Fiction-by-Nicole-Foster.pdf
    • http://loaminoo.linkpc.net/8099095090090091/Wet-True-Lesbian-Sex-Stories-by-Nicole-Foster.pdf
    • http://loaminoo.linkpc.net/3090090099097093/The-Circlet-Treasury-of-Lesbian-Erotic-Science-fiction-and-fantasy-by-Cecilia-Tan.pdf
    • http://loaminoo.linkpc.net/6092092095098095/LESBIAN-ROMANCE-Lesbian-Romance-Story-The-Coming-Out-An-Unexpected-Adventure----lesbian-romance-lesbian-fiction---by-Juliet-Plaisir.pdf
    • http://loaminoo.linkpc.net/1099093097090/Unspeakably-Erotic-Lesbian-Kink-by-D-L-King.pdf
    • http://loaminoo.linkpc.net/8098099097090/Lesbian-Lust-Erotic-Stories-by-Sacchi-Green.pdf
    • http://loaminoo.linkpc.net/1099093096099/Witches-Princesses-and-Women-at-Arms-Erotic-Lesbian-Fairy-Tales-by-Sacchi-Green.pdf
    • http://loaminoo.linkpc.net/2099095096091098/Fifty-shades-of-Lesbian-My-Daughter-s-Friends-Book-3-erotica-lesbian-Series-about-lesbian-with-my-girlfriends-by-J-D-Killi.pdf
    • http://loaminoo.linkpc.net/1099099099096/Voyages-Out-2-Lesbian-Short-Fiction-by-Julie-Blackwomon.pdf
    • http://loaminoo.linkpc.net/3097090092096091/Worlds-Apart-An-anthology-of-lesbian-and-gay-science-fiction-and-fantasy-by-Camilla-Decarnin.pdf
    • http://loaminoo.linkpc.net/1099092096097/The-Safe-Sea-of-Women-Lesbian-Fiction-1969-1989-by-Bonnie-Zimmerman.pdf
    • http://loaminoo.linkpc.net/8092098094096095/Wolfskins-and-Togas-Lesbian-and-Gay-Historical-Fiction-1870-to-the-Present-by-Sarah-Waters.pdf
    • http://loaminoo.linkpc.net/1097099090090/Black-Like-Us-A-Century-of-Lesbian-Gay-and-Bisexual-African-American-Fiction-by-Devon-W-Carbado.pdf
    • http://loaminoo.linkpc.net/1099097099096/Go-the-Way-Your-Blood-Beats-An-Anthology-of-Lesbian-and-Gay-Literary-Fiction-by-African-American-Writers-by-Shawn-Stewart-Ruff.pdf
    • http://loaminoo.linkpc.net/3091096096091098/Herotica-A-Collection-of-Women-s-Erotic-Fiction-by-Susie-Bright.pdf
    • http://loaminoo.linkpc.net/9098096097091096/The-Good-Parts-The-Best-Erotic-Writing-in-Modern-Fiction-by-J-H-Blair.pdf
    • http://loaminoo.linkpc.net/2090090094098/Macho-Sluts-Erotic-Fiction-by-Patrick-Califia-Rice.pdf
    • http://loaminoo.linkpc.net/8097090092/The-Weight-of-Silence-Nicole-Foster-Thriller-2-by-Gregg-Olsen.pdf
    • http://loaminoo.linkpc.net/3090090095090097/Totally-Herotica-A-Collection-Of-Women-s-Erotic-Fiction-by-Susie-Bright.pdf
    • http://loaminoo.linkpc.net/6095094090098092/Rouge-A-Tres-Petite-Collection-of-Erotic-Micro-Fiction-by-Em-Demaison.pdf
    • http://loaminoo.linkpc.net/2099095096091098/Fifty-shades-of-Lesbian-My-Daughter-s-Friends-Book-3-erotica-lesbian-Series-about-lesbian-with-my-girlfriends-by-