Malicious PDF — malware analysis report

Static analysis result for SHA-256 528e2a278cf854d1…

MALICIOUS

PDF

32.2 KB Authoring application: Nitro PDF
MD5: a5678b3c21539b339dca09e1f4a517d4 SHA-1: 1ba9913d79074c623f07ad69e4e542630a18c9ed SHA-256: 528e2a278cf854d140fb5f21852b8f1deec8edd66c5e02a7a1d0d7e06997a549
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The file is a PDF document identified as malicious by ML classifiers and ClamAV, specifically flagged as Pdf.Phishing.TtraffRobotInstall. The document body contains multiple URLs, one of which is an external URI pointing to another PDF file. This suggests a phishing or malware distribution attempt where the initial PDF serves as a lure to download a secondary malicious payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://campusatwestfield.com/uploads/1/3/0/2/130289379/jusofasuneguv_xebesikexezodev_poxitinida_kirukasake.pdf
    • http://mirrorsofgodslove.org/uploads/1/3/0/7/130775331/1884964.pdf
    • http://diapersanddogfood.com/uploads/1/3/0/6/130621882/f36e6c3.pdf
    • http://palomarpools.com/uploads/1/3/0/7/130775528/1703035.pdf
    • http://bernardobellostudio.com/uploads/1/3/0/6/130620927/130620927.html#video+youtube+acdc+highway+to+hell
    • http://bernardobell

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000101f.bin
b8f1577a833d6ea047a42902b959fb3091fcb72364528c0121069a8b664b3346
pdf-font-stream PDF embedded font (sfnt) at offset 0x101F 7304 bytes