Malicious PDF — malware analysis report

Static analysis result for SHA-256 1288e2158582c147…

MALICIOUS

PDF

79.4 KB
MD5: 140ca13448c10d64930d40b089ca5055 SHA-1: 68b689b39eec041a9852cd9f7f8343216148918c SHA-256: 1288e2158582c147cab299ff482400b6dfbe0fcc6f1e48f3d74216ee706fff7b
108 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF utilizes XFA (XML Forms Architecture) and contains an embedded JavaScript payload. This script is designed to execute malicious code, likely for downloading and executing a second-stage payload, as indicated by the ML_NYX_PDF_MALICIOUS and CLAMAV_DETECTION heuristics. The embedded script itself is heavily obfuscated, making a precise analysis of its actions difficult, but its presence within an XFA form strongly suggests an exploit attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded script payload in PDF stream low PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_0000023c.bin
fe906839e5a0e887843fc24d944a3d1ec9d4b9da0008919903915df04e3ed952
pdf-embedded-script PDF raw stream script payload at offset 0x23C 80624 bytes