MALICIOUS
120
Risk Score
🔏 Digital signature Signature invalid
A signature covers the whole signed byte range — PDF JavaScript is never signed on its own — and does not by itself mean the document is safe.
Malware Insights
MITRE ATT&CK
T1059.007 JavaScript
T1203 Exploitation for Client Execution
T1566.001 Spearphishing Attachment
The sample is a PDF file flagged as malicious by ClamAV (Pdf.Dropper.Agent-6331533-0) and an ML classifier. It contains embedded JavaScript, which is a common method for exploiting PDF vulnerabilities and delivering secondary payloads. The invalid digital signature further suggests malicious intent, as it may be an attempt to deceive users about the document's authenticity.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Dropper.Agent-6331533-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Dropper.Agent-6331533-0
-
PDF digital signature is cryptographically invalid medium PDF_SIGNATURE_INVALIDA signature's CMS failed verification: either the signer's signature over the signed attributes is invalid, or the signed content digest does not match the bytes the ByteRange covers. The signature was tampered with, forged, or the signed content was altered.
-
XFA form low PDF_XFAPDF uses XML Forms Architecture — can contain script logic
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://ns.adobe.com/xdp/ In extracted file (stream_000_off0006d90c.js)
- http://www.xfa.org/schema/xci/3.0/In extracted file (stream_000_off0006d90c.js)
- http://www.xfa.org/schema/xfa-template/2.8/In extracted file (stream_000_off0006d90c.js)
- http://www.xfa.org/schema/xfa-data/1.0/In extracted file (stream_000_off0006d90c.js)
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_000_off0006d90c.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x6D90C | 289498 bytes |
SHA-256: dcefc16710d335e69f60cdd8a0e174d43939d02eaa8dd4c6d7ce4ca63f06495b |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.