Malicious PDF — malware analysis report

Static analysis result for SHA-256 695f32de70c20aab…

MALICIOUS

PDF

10.4 KB
MD5: a8e5a6fd30c5fd96e5572b99fa6004b8 SHA-1: c68878943506740fc9d4051d3b245b71c4807dd5 SHA-256: 695f32de70c20aabecf99fe1616fb17eb355a95457f3ed52b1393eba9ecd20e7
110 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file contains an embedded object and triggers heuristics related to obfuscated names and XFA forms, indicating it is designed to exploit vulnerabilities. ClamAV detected it as malware, and the ML classifier strongly agrees. The embedded file is the primary artifact of interest, likely serving as the malicious payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9989

Heuristics 5

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/1.0/
    • http://www.xfa.org/schema/xfa-template/2.4/
    • http://www.xfa.org/schema/xfa-data/1.0/
    • http://ns.adobe.com/xtd/
    • http://www.xfa.org/schema/xfa-form/2.8/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0001.bin
a9e42c13f40242df18889510a46fb02c639c7e8ce4accd88a3279f8740c38188
pdf-embedded-file PDF EmbeddedFile object 1 at offset 0x76 13408 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).