Malicious PDF — malware analysis report

Static analysis result for SHA-256 3d13df9c1dce3ae8…

MALICIOUS

PDF

100.5 KB
MD5: 10dc318d2b3de8b21afedce04e859ffb SHA-1: 9cbb844cad7dbab6623ea8405ea1ab4a92007131 SHA-256: 3d13df9c1dce3ae8fc2b32fec32e304c63ec47707d035e51f548af47bee393ea
118 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution: Malicious PDF T1059.001 Command and Scripting Interpreter: PowerShell

The file is identified as a malicious PDF by multiple heuristics, including a high-confidence ML classifier and ClamAV detection. The presence of an XFA form and an embedded script payload indicates an attempt to exploit vulnerabilities or execute malicious code. The embedded script likely downloads and executes a second-stage payload, though its exact function is obscured by the PDF structure. The confidence is high due to the strong indicators of maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000246.bin
e2d593eadd0f8e84730d97da20fc4a362fdb19674a2e0320d409941bb4e74cae
pdf-embedded-script PDF raw stream script payload at offset 0x246 102150 bytes