Malicious PDF — malware analysis report

Static analysis result for SHA-256 78ac1aeb48f19d8b…

MALICIOUS

PDF

16.1 KB Created: 2019-04-30 02:53:30 +01:00 Authoring application: mPDF 5.7
MD5: 1ea308df2360a778f12b84dd6fcc9eb4 SHA-1: d6c12d6128d300f9c82d7bc6d4bb97c39f094555 SHA-256: 78ac1aeb48f19d8b251296340d3c139f2e03e6ca3d0a8e26b484dfdffe9a4dbf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier as malicious. It contains a large number of embedded links pointing to adult-themed content hosted on the loaminoo.linkpc.net domain. This suggests a social engineering tactic to drive traffic to potentially malicious or unwanted content, rather than direct payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090096092096098095/Young-Sexy-Babe---Book-454-Young-cute-chicks-sexy-photos-by-Johnny-Gunn.pdf
    • http://loaminoo.linkpc.net/9090091090094098/Pussy-Power-No-3-Intimate-Portraits-of-Young-Sexy-Girls-by-Anton-Volkov.pdf
    • http://loaminoo.linkpc.net/3090098099098092/The-Sexy-amp-The-Undead-Sexy-Witches-1-by-Charity-Parkerson.pdf
    • http://loaminoo.linkpc.net/4093093095091091/The-Sexy-Professor-Redemption-The-Sexy-Series-by-T-R-Bertrand.pdf
    • http://loaminoo.linkpc.net/4093093099097095/The-Sexy-Boss-Sedition-The-Sexy-Series-by-T-R-Bertrand.pdf
    • http://loaminoo.linkpc.net/1094095094096090/Sexy-Berkeley-Sexy-1-by-Dani-Lovell.pdf
    • http://loaminoo.linkpc.net/2096094090093090/Sexy-Summers-Sexy-2-by-Dani-Lovell.pdf
    • http://loaminoo.linkpc.net/6090094099097096/Sexy-Hart-Sexy-3-by-Dani-Lovell.pdf
    • http://loaminoo.linkpc.net/1091091094091097093/The-Cuckold-Surrender-Hotwife-Femdom-Interracial-Cuckold-Erotica-with-a-sexy-wife-who-s-crazy-for-BBC-and-will-do-anything-for-a-sexy-black-African-dominant-to-be-her-stud-by-Ronnie-Kinski.pdf
    • http://loaminoo.linkpc.net/1094097097098099/Dirty-Sexy-Cuffed-Dirty-Sexy-3-by-Carly-Phillips.pdf
    • http://loaminoo.linkpc.net/6090095091091096/Sexy-Beast-VIII-Sexy-Beast-8-by-Kate-Douglas.pdf
    • http://loaminoo.linkpc.net/5093097092090093/Death-Stalks-the-Young-Pistolero-Young-Pistolero-Series-Book-3-by-Robert-J-Alvarado.pdf
    • http://loaminoo.linkpc.net/1095095094090091/Jerry-D-Young-s-Survival-Fiction-Library-Book-One-The-Hermit-by-Jerry-D-Young.pdf
    • http://loaminoo.linkpc.net/6090095091091090/Sexy-Beast-VII-Sexy-Beast-7-by-Kate-Douglas.pdf
    • http://loaminoo.linkpc.net/1098098098090093/Sexy-Beast-II-Sexy-Beast-2-by-Kate-Douglas.pdf
    • http://loaminoo.linkpc.net/4098096091096092/Sexy-Jerk-Sexy-Jerk-World-1-by-Kim-Karr.pdf
    • http://loaminoo.linkpc.net/2090095092091/Sexy-Beast-9-Sexy-Beast-9-by-Vonna-Harper.pdf
    • http://loaminoo.linkpc.net/1098097098097092/Dead-Sexy-Dead-Sexy-1-by-Aleah-Barley.pdf
    • http://loaminoo.linkpc.net/1099099095097095/Johnny-Doesn-t-Drink-Champagne-Vampires-of-the-Tower-1-by-Cody-Young.pdf
    • http://loaminoo.linkpc.net/4092094097098098/Sexy-Librarian-s-Big-Book-of-Erotica-by-Rose-Caraway.pdf
    • http://loaminoo.linkpc.net/1091091094091097093/The-Cuckold-Surrender-Hotwife-Femdom-Interracial-Cuckold-Erotica-with-a-sexy-w