Malicious PDF — malware analysis report

Static analysis result for SHA-256 5afb526245ded90c…

MALICIOUS

PDF

41.6 KB Authoring application: pdf-parser
MD5: 7980895615e1bd51b4101c5d28142b6f SHA-1: d449c8f1a6a59dd773e76fc43a84aa9499855b45 SHA-256: 5afb526245ded90c54988549e856c54fa6232657120efe720daa7f1e14189137
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, specifically identified as Pdf.Phishing.TtraffRobotInstall-7605656-0. It contains multiple embedded URLs that likely serve as lures or download locations for further malicious content. The document body, despite being truncated and containing artifacts, attempts to disguise its malicious intent with a topic about time management books.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://nolimitexcavating.com/uploads/1/3/0/2/130287426/ac4a898e95fca.pdf
    • http://xaraf.nedvigimost-mo.ru/uploads/2020/01/29/gafodesakaven.pdf
    • http://mohawklumbercom.com/uploads/1/3/0/6/130639426/881d08.pdf
    • http://ozaymobilyadekorasyon.com/uploads/1/3/0/7/130738484/6431147.pdf
    • http://ankezimmermann.ca/uploads/1/3/0/8/130814562/130814562.html#top+ten+books+on+time+management

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000103d.bin
2030007b5eef56102ff6a738f187e7ef740216abc6a03e8600128ab28dc61f56
pdf-font-stream PDF embedded font (sfnt) at offset 0x103D 8016 bytes