Malicious PDF — malware analysis report

Static analysis result for SHA-256 e5a5200ffcba114b…

MALICIOUS

PDF

17.8 KB Created: 2019-04-30 05:32:05 +01:00 Authoring application: mPDF 5.7
MD5: 7893e0590478ecc66a9fddf6a4c11c37 SHA-1: b0d43c7732cf839636a460056105615fbb0453c1 SHA-256: e5a5200ffcba114b99f11a3a51b2bf2e94b1cd7f0fbc3b8f51a0be0c3dccd209
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a link farm, with numerous embedded URLs pointing to external PDF documents. While the document body is unreadable, the presence of a large number of links suggests a tactic to manipulate search engine results or redirect users to potentially malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090095098092094097/Bikini-Queen-In-nur-28-Tagen-zur-perfekten-Bikinifigur-by-Alina-K-nig.pdf
    • http://loaminoo.linkpc.net/1090095099097098094/Deutsch-in-30-Tagen-German-in-30-Days-Deutsch-in-30-Tagen-German-in-30-Days-Buch-mit-CD-by-Angelika-G-Beck.pdf
    • http://loaminoo.linkpc.net/1090095098093090096/Die-sexuelle-Disziplinierung-des-Mannes-Der-Weg-zur-perfekten-Domina-by-Kim-Powers.pdf
    • http://loaminoo.linkpc.net/1090095098092095097/Astrofotografie-Von-der-richtigen-Ausr-stung-bis-zum-perfekten-Foto-by-Thierry-Legault.pdf
    • http://loaminoo.linkpc.net/1090095098093092093/sch-ner-kochen---Salat-Die-Kunst-der-perfekten-Salatzubereitung-by-Tobias-Rauschenberger.pdf
    • http://loaminoo.linkpc.net/1090095098093091092/Designer-in-60-Minuten---Mit-wenigen-Regeln-zur-perfekten-Visitenkarte-by-Marcus-Kaspar.pdf
    • http://loaminoo.linkpc.net/1090097095090096095/Freude-an-der-Herrschaft-by-Alina-Kein.pdf
    • http://loaminoo.linkpc.net/2092093091095094/Bikini-Planet-by-David-S-Garnett.pdf
    • http://loaminoo.linkpc.net/6095093094095094/The-Butcher-and-Other-Erotica-by-Alina-Reyes.pdf
    • http://loaminoo.linkpc.net/2098090099095099/Low-Tide-Bikini-by-Lyla-Dune.pdf
    • http://loaminoo.linkpc.net/6095093094090099/Dating-The-Prince-What-If-1-by-Alina-Snow.pdf
    • http://loaminoo.linkpc.net/1091097094095097090/Verf-hren-und-Erobern---Crashkurs-f-r-s-FLIRTEN-Werden-Sie-zum-perfekten-Verf-hrer-by-Angelina-Diaz.pdf
    • http://loaminoo.linkpc.net/1090095098092094093/DAS-TURBOGELD-GEHEIMNIS---Ihr-Wegweiser-zum-perfekten-Infoprodukt-ebook-deutsch-by-Aurel-Sieger.pdf
    • http://loaminoo.linkpc.net/6095093094093099/Lifelights-The-Lifelight-Series-1-by-Alina-Voyce.pdf
    • http://loaminoo.linkpc.net/1099099096095095/White-Bikini-Panties-by-Kelly-James-Enger.pdf
    • http://loaminoo.linkpc.net/3090093093099090/Bikini-Shopping-with-Stepdaughter-Hot-Sex-Story-by-Greg-P-Davies.pdf
    • http://loaminoo.linkpc.net/6095093095091090/Angel-s-Feather-Flyer-Chronicles-1-by-Alina-Popescu.pdf
    • http://loaminoo.linkpc.net/8097099098096096/Dunkle-Zwillinge---Finstere-M-chte-by-Alina-Mahn.pdf
    • http://loaminoo.linkpc.net/3099090095093092/Table-Talk-Memoirs-of-a-Bikini-Waxer-by-Caren-A-Stein.pdf
    • http://loaminoo.linkpc.net/2093099099092090/Pure-Love-of-the-Fallen-Lost-Angels-1-by-Alina-Popescu.pdf