Malicious PDF — malware analysis report

Static analysis result for SHA-256 1ffc8485f9136a84…

MALICIOUS

PDF

15.1 KB Created: 2019-04-30 04:19:06 +01:00 Authoring application: mPDF 5.7
MD5: 3d2fcf59781d221dea5cef5406642a24 SHA-1: ffff9f9f0df034ff772f19cb8f224ff1a5fba4cb SHA-256: 1ffc8485f9136a84485ee923800ec8d63a5c8798574811ce82f8912e70d7bfac
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain 'loaminoo.linkpc.net'. This heuristic firing suggests a link farm or a method to distribute further malicious content. While the document body is heavily obfuscated, the presence of numerous links points to a social engineering or redirection attack. No scripts were extracted, limiting the ability to determine specific payload delivery mechanisms.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1099095094092092/Playing-With-The-Drummer-Head-Over-Heels-3-by-Robin-Covington.pdf
    • http://loaminoo.linkpc.net/3095099095096091/Get-Lucky-by-Robin-Covington.pdf
    • http://loaminoo.linkpc.net/1091093097095/One-Little-Kiss-by-Robin-Covington.pdf
    • http://loaminoo.linkpc.net/3092097091094091/Her-Secret-Lover-What-Happens-In-Vegas-11-by-Robin-Covington.pdf
    • http://loaminoo.linkpc.net/3090090099091099/Secret-Santa-Baby-by-Robin-Covington.pdf
    • http://loaminoo.linkpc.net/4090096094091090/Rush-The-MacKenzie-Family-10-7-by-Robin-Covington.pdf
    • http://loaminoo.linkpc.net/2099096096094097/His-Southern-Temptation-The-Boys-are-Back-in-Town-2-by-Robin-Covington.pdf
    • http://loaminoo.linkpc.net/4093090092099092/Southern-Nights-amp-Secrets-The-Boys-are-Back-in-Town-4-by-Robin-Covington.pdf
    • http://loaminoo.linkpc.net/2095096098093/A-Night-of-Southern-Comfort-The-Boys-are-Back-in-Town-1-by-Robin-Covington.pdf
    • http://loaminoo.linkpc.net/1091093095090099/Playing-the-Part-by-Darcy-Daniel.pdf
    • http://loaminoo.linkpc.net/8092097099097/Playing-the-Part-A-Class-of-Their-Own-3-by-Jen-Turano.pdf
    • http://loaminoo.linkpc.net/3098094093097097/Playing-the-Part-by-Kimberly-Van-Meter.pdf
    • http://loaminoo.linkpc.net/2091095095096098/How-to-Be-Famous-Our-Guide-to-Looking-the-Part-Playing-the-Press-and-Becoming-a-Tabloid-Fixture-by-Heidi-Montag.pdf
    • http://loaminoo.linkpc.net/8091093096096/The-Ladies-of-Covington-Send-Their-Love-Ladies-of-Covington-1-by-Joan-Medlicott.pdf
    • http://loaminoo.linkpc.net/1091095095099098090/Playing-for-Keeps-Playing-Series-Book-3-by-Ashlie-Knapp.pdf
    • http://loaminoo.linkpc.net/7094094097093092/The-Brigade-by-H-A-Covington.pdf
    • http://loaminoo.linkpc.net/7096095090098099/Amber-Diceless-Role-Playing-Diceless-Role-Playing-System-by-Erick-Wujcik.pdf
    • http://loaminoo.linkpc.net/4097098099092094/Confessions-of-a-Single-Father-by-Jim-Covington.pdf
    • http://loaminoo.linkpc.net/1091093099096093/Bird-of-Paradise-by-Vicki-Covington.pdf
    • http://loaminoo.linkpc.net/2092093095094099/Gathering-Home-by-Vicki-Covington.pdf