Malicious PDF — malware analysis report

Static analysis result for SHA-256 3b039ba75ec16426…

MALICIOUS

PDF

100.7 KB
MD5: cc12ce4353b7eaee11e3e62fb178f396 SHA-1: b21887e4f802b199fb3c2135e47a269a31105c31 SHA-256: 3b039ba75ec16426dcaacea1de6fde3d572c1b0f8aefd808cd1c0b5bebe14c8b
118 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution: Malicious PDF T1059.001 Command and Scripting Interpreter: PowerShell

The PDF was flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Exploit.Agent-6136306-0' and an ML classifier indicating high maliciousness. The presence of an XFA form and an embedded script payload suggests an exploit targeting PDF reader vulnerabilities. The embedded script is likely responsible for downloading and executing a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000246.bin
4bd61c2aa3ba857c8b75a2bb9ced3de97099ef894ae1b3ebae034d5e80e846dc
pdf-embedded-script PDF raw stream script payload at offset 0x246 102347 bytes