Malicious PDF — malware analysis report

Static analysis result for SHA-256 67dda15eec29a1dd…

MALICIOUS

PDF

97.1 KB
MD5: bb7e0fb754c05c6b61221a91bfe791c7 SHA-1: 01849c22f36d9b8ad92ca286187d85acb2efc6da SHA-256: 67dda15eec29a1dd71950148cdf0fda33b3830a7f568e9d8f1a62cfe3cc3d65d
108 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains embedded JavaScript, indicated by the 'PDF_EMBEDDED_SCRIPT_PAYLOAD' heuristic and the presence of script content. ClamAV detected this as 'Pdf.Exploit.Agent-6136306-0', suggesting it exploits a known vulnerability. The script's obfuscated nature and truncated content prevent a precise analysis of its actions, but it is highly probable that it attempts to download and execute a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded script payload in PDF stream low PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_0000026c.bin
3e8cb7842a651db9e23fc379bb5f0406944a20fd84ff871a0f30d1460dbdcc22
pdf-embedded-script PDF raw stream script payload at offset 0x26C 98659 bytes