Malicious PDF — malware analysis report

Static analysis result for SHA-256 a32a55e13d427457…

MALICIOUS

PDF

18.5 KB Created: 2019-05-02 18:44:34 +01:00 Authoring application: mPDF 5.7
MD5: 36e55a6612d80241a6d45e17a87387a1 SHA-1: 33f5e60fa6b7d2afab0b33651b4c0db4bcf0560a SHA-256: a32a55e13d427457575b5869fd9183f8198968af00e6074e165f52a2cd458069
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link farm with 32 external PDF links, predominantly hosted on loaminoo.linkpc.net. This heuristic strongly suggests a social engineering tactic to direct users to potentially malicious content. No scripts were extracted, and the document body was unreadable, but the presence of numerous external links is a clear indicator of a malicious distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.lin
    • http://loaminoo.linkpc.net/6097095090090094/Heat-Lesbian-Erotica-by-Marion-Picault.pdf
    • http://loaminoo.linkpc.net/2099095096091098/Fifty-shades-of-Lesbian-My-Daughter-s-Friends-Book-3-erotica-lesbian-Series-about-lesbian-with-my-girlfriends-by-J-D-Killi.pdf
    • http://loaminoo.linkpc.net/1091098099096091096/Best-Lesbian-Erotica-1996-by-Tristan-Taormino.pdf
    • http://loaminoo.linkpc.net/3097098090095096/Lesbian-Erotica-Volume-3-by-Barbara-Cardy.pdf
    • http://loaminoo.linkpc.net/1099095098099/Best-Lesbian-Erotica-2011-by-Kathleen-Warnock.pdf
    • http://loaminoo.linkpc.net/8091091091093094/Best-Lesbian-Erotica-2006-by-Tristan-Taormino.pdf
    • http://loaminoo.linkpc.net/1099095094090/Women-With-Handcuffs-Lesbian-Cop-Erotica-by-Sacchi-Green.pdf
    • http://loaminoo.linkpc.net/4092098096091092/EROTICA-Lesbian-Romance-The-Offer-Box-sets-by-J-D-Killi.pdf
    • http://loaminoo.linkpc.net/6097094098098097/Picasso-Picault-Picault-Picasso-A-Magic-Moment-in-Vallauris-1948-1953-by-Sylvie-Vautier.pdf
    • http://loaminoo.linkpc.net/1090098095091093098/Going-Gaga-for-a-Girl-Five-First-Lesbian-Sex-Erotica-Stories-by-Geena-Flix.pdf
    • http://loaminoo.linkpc.net/1090098095090092096/Tied-Up-and-Taken-by-the-Hot-Photographer-My-First-Lesbian-Experience-A-Rough-Sex-Erotica-Story-with-Bondage-by-Geena-Flix.pdf
    • http://loaminoo.linkpc.net/6092092095098095/LESBIAN-ROMANCE-Lesbian-Romance-Story-The-Coming-Out-An-Unexpected-Adventure----lesbian-romance-lesbian-fiction---by-Juliet-Plaisir.pdf
    • http://loaminoo.linkpc.net/4091094091095095/Kinky-Cop-Submission-Erotica-BDSM-Erotica-Series-Book-4-by-Fetish-Publishing.pdf
    • http://loaminoo.linkpc.net/3093091091096099/Sex-Under-the-Same-Roof-3-Seduction-Taboo-Erotica-Blurred-Lines-Erotica-Going-Beyond-50-Shades-of-Grey-by-Tabby-Boo.pdf
    • http://loaminoo.linkpc.net/6097095090090093/Moi-Je-In-Extenso-by-Aude-Picault.pdf
    • http://loaminoo.linkpc.net/6097094099090091/Famille-Pirate---Tome-2---L-Imposteur-by-Aude-Picault.pdf
    • http://loaminoo.linkpc.net/4092095093099/Heat-Wave-Nikki-Heat-1-by-Richard-Castle.pdf
    • http://loaminoo.linkpc.net/3090093097091094/Naked-Heat-Nikki-Heat-2-by-Richard-Castle.pdf
    • http://loaminoo.linkpc.net/1092093095090094/Desert-Heat-Heat-Series-by-Leigh-Wyndfield.pdf
    • http://loaminoo.linkpc.net/8096097092097/Slow-Heat-Pacific-Heat-2-by-Jill-Shalvis.pdf