Malicious PDF — malware analysis report

Static analysis result for SHA-256 b37680ac2e9e4cfd…

MALICIOUS

PDF

50.7 KB Created: 2020-08-31 04:21:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-05-08
MD5: 7004b8edae6a02f05113add0a340c915 SHA-1: ab850c1e5aa02460c6d42b956e17c4b3dd10c237 SHA-256: b37680ac2e9e4cfd64f0225d33f710634b147a42d9c3a118566e5823ae60e872
194 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.club/wix?keyword=la+cajita+feliz+del+metro'. Additionally, it exhibits a PDF link farm heuristic, with numerous links to PDFs hosted on cdn.shopify.com. The document body contains obfuscated text that includes the malicious redirector URL, suggesting an attempt to lure users to a malicious site. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=la+cajita+feliz+del+metro In PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://cdn.shopify.com/s/files/1/0434/9113/1557/files/6558643806.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0432/5117/1478/files/76822551461.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0438/3024/7584/files/the_captain_s_daughter_pushkin.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/puwojadudabub.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0432/8207/1716/files/prepositions_of_place_agenda_web.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0433/0065/1158/files/bare_infinitive_and_full_infinitive_exercises.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0462/3925/2631/files/jevagisukeworebalimupiro.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0436/4104/5145/files/animals_for_kids_vocabulary.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/73930450062.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0432/5834/7688/files/candidose_oesophagienne.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0440/4926/8886/files/50466087353.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0433/0265/0011/files/7th_grade_math_experimental_probability_worksheets.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0429/4439/7468/files/45862072848.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0434/7835/2022/files/best_internet_accountability_software_for_android.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006fea.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6FEA 5056 bytes
SHA-256: 69d65f99a0dc354a7d1528cc643526121ec393baf5f443442de8ead2d2572a8a
font_01_sfnt_off00008110.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8110 11856 bytes
SHA-256: 348e8d5fd97559578da4ad5cc06cdc939906f3cad42e36a4af6db25328cfe807
font_02_sfnt_off0000a7ea.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA7EA 16076 bytes
SHA-256: 20dc835fdb26e5c8b2bf371a74de3f1f2251d0d540cd54084ecb3d27d8cc4587