Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba9abf38f653afc8…

MALICIOUS

PDF

44.1 KB Authoring application: PDFedit First seen: 2026-05-09
MD5: ce9d09280e38fe1ac6394a7896721347 SHA-1: cfc6585b7b82ba35ff0ef19ccd9e083853f4f65c SHA-256: ba9abf38f653afc8fa42eacebed6641b032ebcb695f711cf3d9524e63861d6cd
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF that contains embedded URLs pointing to other PDF files, suggesting a phishing or malware distribution attempt. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier output strongly indicate malicious intent. The embedded URLs are likely used to deliver a second-stage payload or lead the user to a phishing site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rollershadeiq.com/uploads/1/3/0/4/130491488/posazefotu.pdf PDF link annotation
    • http://tonypandytaxiservices.com/uploads/1/3/0/3/130313037/3682595.pdfIn PDF document text
    • http://morby.icu/uploads/2020/01/28/xuxoxamofekewuj.pdfIn PDF document text
    • http://hello-baby-toys.com/uploads/1/3/0/5/130543488/130543488.html#d+d+3.+5+ghostwalkIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00000f9c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF9C 8176 bytes
SHA-256: 8b04f794d2a2ab51faeffc2de957ff19860dc8330d39cc6f1a5cc67f2ee50668
font_01_sfnt_off00006525.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6525 16492 bytes
SHA-256: a88a3252a732d83265545c0d7bca880eac5c53956b7c2c19aa40bc62a0bd5b2d