Malicious PDF — malware analysis report

Static analysis result for SHA-256 410c33f396195da6…

MALICIOUS

PDF

34.7 KB Authoring application: Adobe PDF Library 9.0
MD5: 1eba7eb208a8e585e1970439540ed8a2 SHA-1: 732af24594a13a23133e49d19d742d26f73d2645 SHA-256: 410c33f396195da60754e6ecfb1bcf7734bfb85e038888fb6ae9c7ff5b4fc95d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The file was detected by ClamAV as Pdf.Phishing.TtraffRobotInstall-7605656-0 and flagged by an ML classifier, indicating malicious intent. It contains multiple embedded URLs that redirect to external PDF files or HTML pages. The presence of these external links suggests the PDF is designed to lure users to malicious sites, likely for phishing or to download further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://premiumadultdiapers.com/uploads/1/3/0/6/130603968/jifanogegalidekepo.pdf
    • http://montglass.com/uploads/1/3/0/4/130488934/vojoj.pdf
    • http://leri.cityglush12.icu/uploads/2020/01/29/2027055.pdf
    • http://movimentomarianobetania.org/uploads/1/3/0/5/130544240/kelifiwovuzebuw-sakaxovewedugez-sosaju.pdf
    • http://maxe.igorlucshii.online/uploads/2020/01/28/69deba808ef36.pdf
    • http://dancinggoatsanctuary.com/uploads/1/3/0/2/130272586/130272586.html#cuales+son+los+principios+eticos+fundamentales

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000010ae.bin
dd1cea3b4fdd546f72835775b0a022bd99682c58388455786a1c92eb3b3570f7
pdf-font-stream PDF embedded font (sfnt) at offset 0x10AE 7944 bytes