Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f4c67b9461bd8ed…

MALICIOUS

PDF

14.3 KB Created: 2019-04-30 04:43:01 +01:00 Authoring application: mPDF 5.7
MD5: f3afb2153a3ae83946b3ce177e200063 SHA-1: 3bcebe0c34cc50896c53e1e909c929202a17db77 SHA-256: 9f4c67b9461bd8ed064475fdf03a468be257655e53101ec518fc423e7144fe2e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM' heuristic. These links predominantly point to book download sites hosted on 'loaminoo.linkpc.net', suggesting a lure for users seeking pirated content. While the ML classifier strongly indicates maliciousness, the specific intent appears to be social engineering through the distribution of potentially harmful links rather than direct payload delivery from the PDF itself. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3096096098094/The-Hunters-Brotherband-Chronicles-3-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/3095094095/The-Ghostfaces-Brotherband-Chronicles-6-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/3098097099091093/The-Caldera-Brotherband-Chronicles-7-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/3097096094098/The-Invaders-Brotherband-Chronicles-2-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/5094095095091091/Freres-D-Armes-Feuilleton-Brotherband-1-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/9093090098097094/Die-Belagerung-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/3092097097091/The-Ruins-of-Gorlan-Ranger-s-Apprentice-1-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/2091093096098099/The-Ruins-of-Gorlan-Ranger-s-Apprentice-1-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/6094095096090/The-Battle-for-Skandia-Rangers-Apprentice-4-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/3094091097094/The-Emperor-of-Nihon-Ja-Ranger-s-Apprentice-10-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/6093090097091/The-Ruins-of-Gorlan-Ranger-s-Apprentice-1-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/3094094096090/Halt-s-Peril-Ranger-s-Apprentice-9-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/4091091090091095/The-Siege-of-Macindaw-Ranger-s-Apprentice-6-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/1098091090094095/Halt-s-Peril-Ranger-s-Apprentice-9-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/3093099099091/The-Siege-of-Macindaw-Ranger-s-Apprentice-6-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/3097090094098/The-Lost-Stories-Ranger-s-Apprentice-11-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/2097092090092096/The-Icebound-Land-Ranger-s-Apprentice-3-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/3093099098090/Erak-s-Ransom-Ranger-s-Apprentice-7-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/4095098097090/Minnesota-s-Literary-Visitors-by-John-Theodore-Flanagan.pdf
    • http://loaminoo.linkpc.net/2097092097092094/The-Burning-Bridge-Ranger-s-Apprentice-2-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/3094091097094/The-Emperor-of-Nihon-Ja-Ranger-s-Apprentice-10-by-John-Fla