Malicious PDF — malware analysis report

Static analysis result for SHA-256 99b7f31646394304…

MALICIOUS

PDF

40.9 KB Authoring application: GIMP First seen: 2026-05-08
MD5: 81766b03d873363bd382f55cb82f766e SHA-1: 8b7d63055ef0470b8961a44c5185124b0a0c1cc0 SHA-256: 99b7f31646394304f7aa66d5a4c909c6f9aa3433881ea089a2d09142b49c9841
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of external links, identified as a PDF_SEO_LINK_FARM heuristic, suggesting a phishing or spam campaign. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall' further supports this. The document body contains urgency language like 'account will be terminated', reinforcing the phishing lure. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://pickapassword.com/uploads/1/3/0/6/130604598/4593688.pdf In PDF document text
    • http://tfamcon.com/uploads/1/3/0/6/130639467/wikolowuke-romewavazig-winawazobamob-vupamuwedatiku.pdfIn PDF document text
    • http://auntkates.com/uploads/1/3/0/3/130323146/1790232.pdfIn PDF document text
    • https://judenonur.weebly.com/uploads/1/3/0/5/130588511/86f6e0f5deea01.pdfIn PDF document text
    • http://my-gama.com/uploads/1/3/0/6/130621757/7132095.pdfIn PDF document text
    • http://racks4retail.com/uploads/1/3/0/3/130323527/f1d1a913d6.pdfIn PDF document text
    • http://cavalcadeofkink.com/uploads/1/3/0/3/130313561/dodunabaget.pdfIn PDF document text
    • http://dayveboy.com/uploads/1/3/0/5/130540208/56aaae.pdfIn PDF document text
    • http://pakalolochocolate.com/uploads/1/3/0/5/130546237/ad77ea67.pdfIn PDF document text
    • http://advancedsteeldetailingltd.com/uploads/1/3/0/3/130323952/4134840.pdfIn PDF document text
    • http://aletothechief.com/uploads/1/3/0/5/130588173/refonar.pdfIn PDF document text
    • http://davidmarquesibanez.com/uploads/1/3/0/3/130323674/130323674.html#toefl+ibt+listening+test+2+-+full+test+with+answer+keysIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001298.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1298 8308 bytes
SHA-256: ec74736ddddf68c8669c0d5c8c0bcc4c34d68b31987d1336f61203136c80abe7
font_01_sfnt_off00005773.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5773 16500 bytes
SHA-256: feb643a66ad04cc3932283c9206cb2ef5de961104b28d4b9cc944e4fab6f0f6b