Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c42d5d889b98dbc…

MALICIOUS

PDF

26.6 KB
MD5: 1e74cd62ec09df3d4772bac92334e06c SHA-1: d2b3033b929dd6b0fe5442a42fa97592efc3268f SHA-256: 3c42d5d889b98dbc4f283084b81b639903765c297315f52c52012e9948e63c8e
106 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1059 Command and Scripting Interpreter

The file is identified as malicious by multiple heuristics, including a critical ClamAV detection for 'Pdf.Exploit.Agent-6136306-0' and a high ML classifier score. The presence of an embedded file and XFA form suggests an exploit attempt. The embedded URL, while not definitively malicious, is associated with the XFA structure, indicating a potential delivery vector for a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9978

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/