Malicious PDF — malware analysis report

Static analysis result for SHA-256 573781307588f47e…

MALICIOUS

PDF

100.7 KB
MD5: f93f82ee99d434e3cd8fb9d8e03bff15 SHA-1: 772f1029cedf04696b17f44f99b642e112d8776d SHA-256: 573781307588f47e9f783688f2eee3307f5516534d05d3e88e4e869711181b42
118 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF was flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Exploit.Agent-6136306-0' and an ML classifier indicating high maliciousness. The presence of an XFA form and an embedded script payload suggests an exploit targeting PDF reader vulnerabilities. The embedded script likely attempts to download and execute a second-stage payload, though its exact functionality is obscured by the PDF structure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000246.bin
0c8c9e4382f510658d16ed28340466d1bf881c36b8c2f046a0243623320a05fc
pdf-embedded-script PDF raw stream script payload at offset 0x246 102374 bytes