Malicious PDF — malware analysis report

Static analysis result for SHA-256 0ebf5ac97f022fa1…

MALICIOUS

PDF

42.0 KB Authoring application: Pdftk First seen: 2026-05-09
MD5: f20a3605658490ae8deb08aaa75e3b48 SHA-1: 462a539afb3d7e8c5836259ad021b28585b932b4 SHA-256: 0ebf5ac97f022fa1a42cf433a5e3267643d0e22f4db588451bfe2af75fba387f
212 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF document exhibits multiple indicators of malicious activity, including a critical heuristic firing for a large number of external PDF links, suggestive of a link farm. The document body, though partially corrupted, contains text related to 'affidavit of support' and payment instructions, aligning with a payment redirection lure. The presence of embedded URLs and the ClamAV detection further support its classification as malicious, likely serving as a phishing or redirection tool.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Payment redirection / bank-detail change lure high SE_PAYMENT_REDIRECT_LURE
    Document describes new or changed bank, wire, ACH, IBAN, SWIFT, or routing instructions — a high-value business-email-compromise pattern
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) or Microsoft license-boilerplate documents that carry no urgency or charge/dispute escalation.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://intentionalfitness.club/uploads/1/3/0/4/130490719/sevufomumivelosawum.pdf In PDF document text
    • http://mexiitem.com/uploads/1/3/0/7/130776502/7792478.pdfIn PDF document text
    • http://mpcaa.net/uploads/1/3/0/6/130603968/6258860.pdfIn PDF document text
    • http://caseylieberman.com/uploads/1/3/0/4/130483766/pobunisutabatugob.pdfIn PDF document text
    • http://thehappyvisionarycoach.com/uploads/1/3/0/7/130775821/e3a4a3b9483a362.pdfIn PDF document text
    • http://auctionsumo.com/uploads/1/3/0/2/130271212/sesadak_muvonirizubum_vobivonexi_sewaboxiluso.pdfIn PDF document text
    • http://rubberbymok.com/uploads/1/3/0/5/130539238/585215.pdfIn PDF document text
    • http://johnsonjaguarband.net/uploads/1/3/0/6/130621435/7384308.pdfIn PDF document text
    • http://sugooi.com/uploads/1/3/0/3/130379143/zajafiridi_pufitade.pdfIn PDF document text
    • http://veteransretreatcenter.com/uploads/1/3/0/6/130604144/sekamiwud_runivaki.pdfIn PDF document text
    • http://smootherwaters.com/uploads/1/3/0/7/130740551/1226f29fce42cb.pdfIn PDF document text
    • http://stilettosandshotguns.com/uploads/1/3/0/6/130639652/260235b793.pdfIn PDF document text
    • http://myleegen.com/uploads/1/3/0/3/130313049/3382928.pdfIn PDF document text
    • http://nicegiant.com/uploads/1/3/0/6/130604772/zugofukapadanaxugato.pdfIn PDF document text
    • http://333-tools.com/uploads/1/3/0/4/130483428/fifuxe.pdfIn PDF document text
    • http://bodyprojecttreatment.com/uploads/1/3/0/6/130639436/7882574.pdfIn PDF document text
    • http://mingrentang.bpmtc.com/uploads/1/3/0/5/130588240/130588240.html#where+to+file+form+i-134+affidavit+of+supportIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004815.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4815 8140 bytes
SHA-256: 50c9f9bdbb18f697aa15e7ac76f11d93b9f0c7b00f2f11337cdd7051ce21f5e7