Malicious PDF — malware analysis report

Static analysis result for SHA-256 6fde728da8911528…

MALICIOUS

PDF

78.0 KB Authoring application: Nitro PDF First seen: 2026-05-08
MD5: 624f275809076d5ffa184ec05ed4f119 SHA-1: ed5fd1c080700e7ec421c3d6f4a2b03451ccb1e9 SHA-256: 6fde728da89115284e69eeb300bf871d86a1ee78edc048a4b921c17ee142e077
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains an embedded URI pointing to a PDF file hosted on altasanacion.net, which is likely a lure to download a second-stage payload. The document body contains obfuscated text and references to legitimate frameworks, likely to appear trustworthy.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9951

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://altasanacion.net/uploads/1/3/0/5/130589430/taludivefowuwiw-jusejomazaz-ruwilemaloxepo-zupevonuleposed.pdf PDF link annotation
    • https://zerorenomurakur.weebly.com/uploads/1/3/0/5/130550981/fecab3.pdfIn PDF document text
    • http://var.site-elit.ru/uploads/2020/01/28/dfefbe1f.pdfIn PDF document text
    • http://gochu.ru/uploads/2020/01/28/sagod.pdfIn PDF document text
    • http://newstylemarket.com/uploads/1/3/0/5/130541384/130541384.html#malcolm+baldrige+performance+excellence+frameworkIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicenseIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
🗂 Part of campaign: shared payload f77ae30e2e 4 samples

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001127.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1127 9184 bytes
SHA-256: ea74ed5db8400d7fb6a1210ffb4d7e64543681befabe6d5249e1a16d72c2b675
font_01_sfnt_off00005e73.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5E73 2600 bytes
SHA-256: 41d5c9cb4d60b7530e3cfd93a78efd430fe179aa57a8296e74fb8a971da4b0ee
font_02_sfnt_off0000ed64.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xED64 16040 bytes
SHA-256: f77ae30e2eec2ca3578253c0a086b7b4bc83d4d366503269d9bfd12176ed9dae