Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca97452ef07ab126…

MALICIOUS

PDF

22.6 KB Created: 2019-04-30 18:51:08 +01:00 Authoring application: mPDF 5.7
MD5: 97abe027764f67b6c648fa79f8c25b62 SHA-1: 307050eaf8bb53f8676dbf75ad653488b3c6d5d1 SHA-256: ca97452ef07ab1267aa57d54ec61a3b4077da89733480c68897a01f14d007929
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded URLs, many of which point to PDF documents with book titles. This suggests a potential SEO poisoning or link farm attack. The primary purpose appears to be directing users to external resources, though the exact malicious payload is not directly executed by this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://zacdsa.linkpc.net/1c55c50c59c51c50/Queen-s-Own-Fool-A-Novel-of-Mary-Queen-of-Scots-by-Jane-Yolen.pdf
    • http://zacdsa.linkpc.net/8c59c54c50c52/Queen-s-Own-Fool-Stuart-Quartet-1-by-Jane-Yolen.pdf
    • http://zacdsa.linkpc.net/7c59c56c51/Daughters-of-the-Winter-Queen-Four-Remarkable-Sisters-the-Crown-of-Bohemia-and-the-Enduring-Legacy-of-Mary-Queen-of-Scots-by-Nancy-Goldstone.pdf
    • http://zacdsa.linkpc.net/4c55c55c52c52c54/Mary-Queen-of-Scots-by-Carolly-Erickson.pdf
    • http://zacdsa.linkpc.net/2c57c52c55c52c58/Mary-Queen-of-Scots-by-Antonia-Fraser.pdf
    • http://zacdsa.linkpc.net/1c55c53c55c59c55/Except-the-Queen-by-Jane-Yolen.pdf
    • http://zacdsa.linkpc.net/1c55c53c54c51c54/Fatal-Majesty-A-Novel-of-Mary-Queen-of-Scots-by-Reay-Tannahill.pdf
    • http://zacdsa.linkpc.net/1c53c59c53c59c52/Lord-Bothwell-and-Mary-Queen-of-Scots-by-Robert-Gore-Browne.pdf
    • http://zacdsa.linkpc.net/4c50c56c55c59c50/A-Question-of-Guilt-A-Novel-of-Mary-Queen-of-Scots-and-the-Death-of-Henry-Darnley-by-Julianne-Lee.pdf
    • http://zacdsa.linkpc.net/6c58c52c53c57c58/Inventaires-de-La-Royne-Descosse-Douairiere-de-France-Catalogues-of-the-Jewels-Dresses-Furniture-Books-and-Paintings-of-Mary-Queen-of-Scots-1556-1569-by-Bannatyne-Club.pdf
    • http://zacdsa.linkpc.net/3c53c59c58c59c59/Mary-Tudor-Courageous-Queen-or-Bloody-Mary-by-Jane-Buchanan.pdf
    • http://zacdsa.linkpc.net/4c50c53c55c55c53/Five-Gold-Rings-A-Royal-Wedding-Souvenir-Album-from-Queen-Victoria-to-Queen-Elizabeth-II-by-Jane-Roberts.pdf
    • http://zacdsa.linkpc.net/3c51c58c57c54/Spy-for-the-Queen-of-Scots-by-Theresa-Breslin.pdf
    • http://zacdsa.linkpc.net/3c53c59c52c51c57/The-Nine-Days-Queen-A-Portrait-of-Lady-Jane-Grey-by-Mary-M-Luke.pdf
    • http://zacdsa.linkpc.net/2c57c54c52c50c52/The-Sisters-Who-Would-Be-Queen-Mary-Katherine-and-Lady-Jane-Grey-A-Tudor-Tragedy-by-Leanda-de-Lisle.pdf
    • http://zacdsa.linkpc.net/8c55c59c54c56c57/The-Queen-s-Fool-The-Tudor-Court-4-by-Philippa-Gregory.pdf
    • http://zacdsa.linkpc.net/3c53c58c59c55c53/Catherine-Howard-The-Queen-Whose-Adulteries-Made-a-Fool-of-Henry-VIII-by-Lacey-Baldwin-Smith.pdf
    • http://zacdsa.linkpc.net/2c53c50c54c56c57/Warrior-Queen-The-Story-of-Boudica-Celtic-Queen-by-Alan-Gold.pdf
    • http://zacdsa.linkpc.net/1c57c58c57c57c53/Counting-One-s-Blessings-The-Selected-Letters-of-Queen-Elizabeth-the-Queen-Mother-by-William-Shawcross.pdf
    • http://zacdsa.linkpc.net/4c57c56c58c55c55/The-Lady-Queen-The-Notorious-Reign-of-Joanna-I-Queen-of-Naples-Jerusalem-and-Sicily-by-Nancy-Goldstone.pdf