Malicious PDF — malware analysis report

Static analysis result for SHA-256 369db58d92e37d10…

MALICIOUS

PDF

93.3 KB
MD5: 97b054f981bbc5225c2d8f100e69a869 SHA-1: 84c7a85b8bbc2dd3a3a244966fb72ea99399d3f4 SHA-256: 369db58d92e37d10b53abe92a0be7e3c7ca51389856c5d5f6534bfd6b1aaca96
178 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF was flagged by multiple heuristics, including ML and ClamAV, indicating malicious intent. The presence of an XFA form and an embedded script payload suggests an exploit is being used to deliver a secondary stage. The embedded artifact 'embedded_pdf_script_00000246.bin' is likely the malicious component.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000246.bin
c42bd379f8d50587933d5676f234c21fe35ab5bea6843bc69f2d55bb4d98d5f1
pdf-embedded-script PDF raw stream script payload at offset 0x246 94820 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36769
Obfuscation or payload: unlikely