Malicious PDF — malware analysis report

Static analysis result for SHA-256 564a20a453ae1354…

MALICIOUS

PDF

13.3 KB
MD5: 1aa139baaaa007c7c9dec25bad226b04 SHA-1: 5031c045a3814ef86589dcaf62bd325a0773aa1d SHA-256: 564a20a453ae13544bf76c9d32b9242e32237d4855d9af513530b6e4a531d101
66 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1059.001 PowerShell

The PDF file contains an embedded script payload, indicated by the 'PDF_EMBEDDED_SCRIPT_PAYLOAD' heuristic. The ML classifier strongly flags this PDF as malicious. While the document body and embedded URLs do not provide direct clues, the presence of an embedded script suggests an attempt to execute arbitrary code, likely to download and run a second-stage payload. The script itself appears to be obfuscated, making a precise determination of its actions difficult.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0008.bin
64396a4ba7a6dcb6da20f5a97275a8311c5610f361e548a5e2c3cc4b137e9507
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0xD5 12808 bytes