Malicious PDF — malware analysis report

Static analysis result for SHA-256 15074ef5bd5e1615…

MALICIOUS

PDF

42.7 KB Created: 2020-08-07 13:37:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-05-07
MD5: 1f4fa1620a7b7d0ae37854d368ffaf58 SHA-1: a4eeae0acc55d701e83b14cdc50a9ab8a608ff73 SHA-256: 15074ef5bd5e16155c4216e73fe5054d23f41c8ea86ce60d7d7f1d89ab9ed9d8
194 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded links, many pointing to a redirector URL (https://ttraff.ru/pify?keyword=anticorpos+heter%25C3%25B3filos+pdf), which is flagged as malicious. The document body, though heavily obfuscated, also contains this redirector URL and several benign-looking Shopify URLs, suggesting a link farm or SEO poisoning tactic to lure users into downloading malicious content disguised as legitimate PDFs. The ML classifier strongly indicates maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=anticorpos+heter%25C3%25B3filos+pdf In PDF document text
    • http://files.andypresentations.com/uploads/1/3/1/4/131454098/ffa36ad.pdfIn PDF document text
    • http://files.ethanemersonmusic.com/uploads/1/3/0/8/130874284/dirofo.pdfIn PDF document text
    • http://files.artzhc.com/uploads/1/3/1/4/131455158/jakilif.pdfIn PDF document text
    • http://files.glenelder.com/uploads/1/3/2/6/132696280/noxenevi.pdfIn PDF document text
    • http://files.mesbodysculpting.com/uploads/1/3/0/8/130814492/3041233.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://cdn.shopify.com/s/files/1/0433/9341/7366/files/govomadasabazumolawibi.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0430/6881/7562/files/98702895874.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0437/7618/0376/files/organic_chemistry_jones_5th_edition_download.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0440/0077/2246/files/kobofajir.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0428/8118/8003/files/sanalugireburerod.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0437/7185/5002/files/75893564898.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0430/8982/1845/files/32760518478.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0434/7982/6589/files/sibegotixavi.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0431/6263/2360/files/88715011532.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0437/4963/8295/files/46039180509.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0429/3568/1180/files/funelisifunelanid.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006708.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6708 5156 bytes
SHA-256: c251d961b7129de6d2c114c17741b467bd91b685b4f0404a53c11b24363efd7e
font_01_sfnt_off00007851.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7851 11208 bytes
SHA-256: cd7da250ee0aaa7663bc04063d70e0966d775fde44d4d73131f244a8bbd4c00a