Malicious PDF — malware analysis report

Static analysis result for SHA-256 09452719a552e2c0…

MALICIOUS

PDF

100.4 KB
MD5: 117b2b244287a492e934f48fffb2b00f SHA-1: ec275c0db4c8963e598e733889e0d11f0cacfe16 SHA-256: 09452719a552e2c05c7af8abc6ca0c75abe7b19220b4eb4d4005ced29b4ba8a4
108 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV and an ML classifier, with heuristics indicating an XFA form and an embedded JavaScript payload. The embedded script is heavily obfuscated but appears to be designed to download and execute a secondary payload. The benign URLs present are likely decoys or part of the XFA template structure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded script payload in PDF stream low PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000246.bin
c7ef7483ceab6f10b4e3820db725eccb52162b715c3b29369d854b39643be681
pdf-embedded-script PDF raw stream script payload at offset 0x246 102040 bytes