Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e3494f94e838cdb…

MALICIOUS

PDF

12.8 KB Created: 2019-05-07 03:36:34 +01:00 Authoring application: mPDF 5.7
MD5: 95df4d1cd401bf640fa055cb150bd322 SHA-1: f9f34f82f988084b2e597e3a1e4c9af9c6a97c38 SHA-256: 1e3494f94e838cdbff7feec019c6369c139b6d5846db2f52d805486aed6e27ef
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a link farm with numerous embedded URLs, all pointing to the same domain. This heuristic suggests the document is designed to drive traffic to a large collection of external content, likely for SEO manipulation or to host malicious payloads. No scripts were extracted, and the document body was heavily corrupted, limiting further analysis of the specific lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9097096098098092/Junge-Kerle-v-geln-geile-Grannys-by-Zoran-Zecke.pdf
    • http://loaminoo.linkpc.net/9097096098098096/Glockenspiele-Geile-Kerle-unter-sich-by-Thorsten-Lubert.pdf
    • http://loaminoo.linkpc.net/8099099099096090/Die-geile-Elfe-by-Ino-Oe.pdf
    • http://loaminoo.linkpc.net/4098091095096096/Tell-Me-What-You-See-by-Zoran-Drvenkar.pdf
    • http://loaminoo.linkpc.net/5091091099091090/Tell-Me-What-You-See-by-Zoran-Drvenkar.pdf
    • http://loaminoo.linkpc.net/5094092095093096/The-Bridge-by-Zoran-ivkovi-.pdf
    • http://loaminoo.linkpc.net/4098091092092095/The-Library-by-Zoran-ivkovi-.pdf
    • http://loaminoo.linkpc.net/9097096097099096/Kerle-im-Schrank-by-Thomas-Hembek.pdf
    • http://loaminoo.linkpc.net/9097096097099094/Dominante-Kerle-6-in-1-by-Alice-Deeper.pdf
    • http://loaminoo.linkpc.net/1098094096099/The-City-ABC-Book-by-Zoran-Milich.pdf
    • http://loaminoo.linkpc.net/1097095094096093/Steps-Through-the-Mist-by-Zoran-ivkovi-.pdf
    • http://loaminoo.linkpc.net/9098090096092/12-Collections-amp-the-Teashop-by-Zoran-ivkovi-.pdf
    • http://loaminoo.linkpc.net/1090095094095091097/Republic-of-Georgia-by-Zoran-Pavlovic.pdf
    • http://loaminoo.linkpc.net/5094092095098092/The-Book-The-Writer-by-Zoran-ivkovi-.pdf
    • http://loaminoo.linkpc.net/5094092095092095/Impossible-Encounters-by-Zoran-ivkovi-.pdf
    • http://loaminoo.linkpc.net/1097095094096095/Impossible-Stories-II-by-Zoran-ivkovi-.pdf
    • http://loaminoo.linkpc.net/9094095090092091/Geile-Sexsklavin-gesucht-by-Niklas-Larsen.pdf
    • http://loaminoo.linkpc.net/9097096098099094/F-nf-Mal-Kerle-und-Geburtstage-by-Sissi-Kaipurgay.pdf
    • http://loaminoo.linkpc.net/9097096098097096/Im-Schatten-meiner-selbst-by-Linda-Kerle.pdf
    • http://loaminoo.linkpc.net/9097096098098093/Gay-Hardcore-06-Schussbereite-Kerle-by-Tilman-Janus.pdf
    • http://loaminoo.linkpc.net/1090095094095091097/Republic-of-Georgia-by-Zo