Malicious PDF — malware analysis report

Static analysis result for SHA-256 ffb61ef0cf3c3f29…

MALICIOUS

PDF

18.7 KB Created: 2019-05-05 15:48:31 +01:00 Authoring application: mPDF 5.7
MD5: 62cb455c1878455803d07c929b7f60c4 SHA-1: 2698ff7e1961d9b2c1566ac1e3e04d6ae9eed68e SHA-256: ffb61ef0cf3c3f29631ad07e27981a1f1967922546bfdc62a3137f72bcabf93a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves appear to point to book-related content and are marked as confirmed benign, the sheer volume and the nature of the heuristic suggest a potential attempt at SEO manipulation or a lure to a malicious site disguised as legitimate content. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the direct intent.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.lin
    • http://loaminoo.linkpc.net/6095090098095092/Marcella-s-Italian-Kitchen-by-Marcella-Hazan.pdf
    • http://loaminoo.linkpc.net/6095090099095094/Marcella-Says-Italian-Cooking-Wisdom-from-the-Legendary-Teacher-s-Master-Classes-with-120-of-Her-Irresistible-New-Recipes-by-Marcella-Hazan.pdf
    • http://loaminoo.linkpc.net/3090098093096090/More-Classic-Italian-Cooking-by-Marcella-Hazan.pdf
    • http://loaminoo.linkpc.net/6095090098095091/Amarcord-Marcella-Remembers-by-Marcella-Hazan.pdf
    • http://loaminoo.linkpc.net/6095090099092091/A-Bitter-Chill-An-Aurelia-Marcella-Roman-Mystery-Aurelia-Marcella-Roman-Series-by-Jane-Finnis.pdf
    • http://loaminoo.linkpc.net/4099099091095094/Marcella-by-Mrs-Humphry-Ward.pdf
    • http://loaminoo.linkpc.net/6095090098095099/Marcella-by-Marilyn-Coffey.pdf
    • http://loaminoo.linkpc.net/2091093091095099/Nightmare-Ink-Living-Ink-1-by-Marcella-Burnard.pdf
    • http://loaminoo.linkpc.net/6095090099091091/Marcella-s-Awakening-by-Johnny-Dorsey.pdf
    • http://loaminoo.linkpc.net/6095091090090092/Marcella-by-Mary-Arnold-Ward.pdf
    • http://loaminoo.linkpc.net/1092099095094/Of-Rascals-And-Rainbows-by-Marcella-Thompson.pdf
    • http://loaminoo.linkpc.net/4091097095090090/Bound-by-Ink-Living-Ink-2-by-Marcella-Burnard.pdf
    • http://loaminoo.linkpc.net/6095090098097091/Marcella-A-Raggedy-Ann-Story-by-Johnny-Gruelle.pdf
    • http://loaminoo.linkpc.net/6095090099091094/Danger-in-the-Wind-Aurelia-Marcella-4-by-Jane-Finnis.pdf
    • http://loaminoo.linkpc.net/6095090098097098/A-Bitter-Chill-Aurelia-Marcella-2-by-Jane-Finnis.pdf
    • http://loaminoo.linkpc.net/4097096095098095/Call-of-the-Witch-Tony-Marcella-Mysteries-7-by-Dana-E-Donovan.pdf
    • http://loaminoo.linkpc.net/6095090099096094/Organizational-Culture-Change-Unleashing-Your-Organization-s-Potential-in-Circles-of-10-by-Marcella-Bremer.pdf
    • http://loaminoo.linkpc.net/8094090097091099/Chloe-s-Vegan-Italian-Kitchen-150-Pizzas-Pastas-Pestos-Risottos-amp-Lots-of-Creamy-Italian-Classics-by-Chloe-Coscarelli.pdf
    • http://loaminoo.linkpc.net/4097096095098097/Return-Of-The-Witch-Detective-Marcella-Witch-s-series-9-by-Dana-E-Donovan.pdf
    • http://loaminoo.linkpc.net/8095097099092095/Gennaro-s-Italian-Family-Favourites-Authentic-recipes-from-an-Italian-kitchen-by-Gennaro-Contaldo.pdf