Malicious PDF — malware analysis report

Static analysis result for SHA-256 61e4d4b41007cbac…

MALICIOUS

PDF

79.4 KB
MD5: 08e2e95aa4dfa2a96713586c10a13c3f SHA-1: 70774468c3e27b83e67a7ba54caed7f1a80fb8ac SHA-256: 61e4d4b41007cbac7eb91dc3e5317b26643b68f1ebc3264c7fecc4e644c20891
108 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

This PDF file was flagged as malicious by ClamAV and an ML classifier, indicating it contains an exploit. The presence of an embedded JavaScript script within a PDF stream, combined with XFA form elements, strongly suggests the script is designed to be executed upon opening the document. While the script is heavily obfuscated and truncated, its structure implies it attempts to download and execute a secondary payload, a common technique for malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded script payload in PDF stream low PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_0000023c.bin
aa63660ef54421f4fa2f0f39e87b53c38d8c73cf957f9cce76d6b5cbee5c1d15
pdf-embedded-script PDF raw stream script payload at offset 0x23C 80624 bytes