Malicious PDF — malware analysis report

Static analysis result for SHA-256 c880cb06f860df72…

MALICIOUS

PDF

13.8 KB Created: 2019-05-02 05:24:40 +01:00 Authoring application: mPDF 5.7
MD5: 19238f4384701e3614b2dfa35bbc8717 SHA-1: 2422aa0d4bffb3496c73ecb5099dfafbdbe26636 SHA-256: c880cb06f860df72fb593873af35e25d36ee482ed85ecc0186cb0c24366e8c66
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, hosted on the domain 'loaminoo.linkpc.net'. This heuristic firing, combined with the ML classifier's high confidence, indicates a malicious intent to direct users to a link farm. The document body confirms the presence of these links, suggesting a lure or redirection tactic rather than direct content delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091092096094098095/Alistair-MacLean-s-Time-of-the-Assassins-by-Alastair-MacNeill.pdf
    • http://loaminoo.linkpc.net/1091092096094098097/Alistair-MacLean-s-Rendezvous-by-Alastair-MacNeill.pdf
    • http://loaminoo.linkpc.net/4091090093098092/The-Satan-Bug-by-Alistair-MacLean.pdf
    • http://loaminoo.linkpc.net/5094090095094090/The-Last-Frontier-by-Alistair-MacLean.pdf
    • http://loaminoo.linkpc.net/4090091097090/HMS-Ulysses-by-Alistair-MacLean.pdf
    • http://loaminoo.linkpc.net/1093098094094093/Athabasca-by-Alistair-MacLean.pdf
    • http://loaminoo.linkpc.net/4091090098094/Night-Without-End-by-Alistair-MacLean.pdf
    • http://loaminoo.linkpc.net/3098097092096097/Santorini-by-Alistair-MacLean.pdf
    • http://loaminoo.linkpc.net/1094090090098094/Bear-Island-by-Alistair-MacLean.pdf
    • http://loaminoo.linkpc.net/3098094097097095/Bear-Island-by-Alistair-MacLean.pdf
    • http://loaminoo.linkpc.net/1090091099097099099/Where-Eagles-Dare-by-Alistair-MacLean.pdf
    • http://loaminoo.linkpc.net/2094096091096097/The-Way-to-Dusty-Death-by-Alistair-MacLean.pdf
    • http://loaminoo.linkpc.net/7099095095090/The-Guns-of-Navarone-by-Alistair-MacLean.pdf
    • http://loaminoo.linkpc.net/4093095096091096/Time-Assassins-Time-Assassins-1-by-R-Kyle-Hannah.pdf
    • http://loaminoo.linkpc.net/4098095092097093/Time-of-the-Assassins-by-Hugh-Holton.pdf
    • http://loaminoo.linkpc.net/2092090095091094/Doctor-Who-Harvest-of-Time-by-Alastair-Reynolds.pdf
    • http://loaminoo.linkpc.net/2091094095097092/A-Head-For-Assassination-Time-Travelling-Assassins-1-by-Gayle-Ramage.pdf
    • http://loaminoo.linkpc.net/2093095098097092/Niall-and-the-Stone-of-Destiny-Book-I-by-Lance-MacNeill.pdf
    • http://loaminoo.linkpc.net/8090094095092095/Elixir-and-Necropolis-by-Alastair-Hunter-by-Alastair-Hunter.pdf
    • http://loaminoo.linkpc.net/6093093099097/The-Collected-Poems-of-Alistair-Te-Ariki-Campbell-by-Alistair-Te-Ariki-Campbell.pdf
    • http://loaminoo.linkpc.net/4098095092097093/Time-of-the-Assassins-by-Hugh-Holton