Malicious PDF — malware analysis report

Static analysis result for SHA-256 065c3b9dfb5f9a29…

MALICIOUS

PDF

79.3 KB
MD5: b4f4476ee81f9998cb719b847a046bff SHA-1: 49d95db830d09f06e9c52122d9d66a785c7fc870 SHA-256: 065c3b9dfb5f9a2966150aeced11f95774de6cd2157cceb7f6af65e05a2c139d
168 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF was flagged as malicious by multiple engines, including ClamAV, and exhibits characteristics of XFA form exploitation. Embedded JavaScript was found within a PDF stream, which is designed to execute code. This script likely attempts to download and execute a second-stage payload, a common technique for initial compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded script payload in PDF stream low PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_0000023e.bin
dbbbc4faf87c51b84ead9d65cd8669de4c50dc4b1c5284a0955d56de3f83fa76
pdf-embedded-script PDF raw stream script payload at offset 0x23E 80469 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36769
Obfuscation or payload: unlikely