Malicious PDF — malware analysis report

Static analysis result for SHA-256 d75588f1eee03f64…

MALICIOUS

PDF

41.8 KB Created: 2020-08-14 13:04:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-05-08
MD5: 385f63af08ee4b6b657e78ddf06bd84e SHA-1: 47d8c1c37edd6c3d3f08f4429b05784a4cbe7fa2 SHA-256: d75588f1eee03f64c22048a6fe600591cb92036919d0f46d39e0027361febb33
162 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains embedded links that point to a known malicious redirector, ttraff.com, which is likely intended to lure users into downloading malware. The document body, though heavily obfuscated, contains text referencing 'collage maker apkpure' and the malicious URL, reinforcing the phishing pretext. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • SEO-redirector lure link (multi-word utm_term) low PDF_SEO_UTM_REDIRECTOR_LINK
    PDF contains a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the search-keyword gateway used by the 'free document download' phishing family. Surfaced as an IOC; on its own this is a low-confidence signal.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=collage+maker++apkpure In PDF document text
    • http://sukokegag.cowlitzcountycjac.com/uploads/1/3/2/6/132695492/9913820.pdfIn PDF document text
    • http://betiboz.wovenbygraceboutique.com/uploads/1/3/2/6/132682883/megelar-nofilagol.pdfIn PDF document text
    • http://files.grandcelticpipeband.com/uploads/1/3/1/3/131379181/167166.pdfIn PDF document text
    • http://files.littleheartrocks.com/uploads/1/3/0/8/130814124/111038.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://cdn.shopify.com/s/files/1/0440/2341/4942/files/5762460258.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0434/4276/5976/files/movukibalibexepiminixaj.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0435/9513/7187/files/psychology_openstax.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0434/7317/4680/files/52488486002.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0431/5106/5243/files/jagezavetigusulutufuboz.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0429/2725/9811/files/mezasurewofuvuxiro.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0435/2668/4824/files/97428561945.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0435/5670/0319/files/48226649218.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0447/8962/9079/files/download_novel_arifureta_shokugyou_de_sekai_saikyou_bahasa_indonesia.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0433/8545/4757/files/94605800347.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000475c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x475C 4932 bytes
SHA-256: 86db3e38fb90e1e70f81a4b725a7123eb509a55c8287bec5b6a2b0197790c467
font_01_sfnt_off0000580d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x580D 2188 bytes
SHA-256: 8243a2978354b99ad9fc1765d3878328d49e2998d0a5549394a0bdfef85e0506
font_02_sfnt_off0000622c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x622C 10148 bytes
SHA-256: d1a29c12564d8f487a89a85c1766bd94860c45e097d0e737cf6d065a11c48fc3
font_03_sfnt_off00008514.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8514 16092 bytes
SHA-256: 39b2f4b99ee08965fd4836f89f628a00cde8346cb181131bba0308e80db8fb67