Malicious PDF — malware analysis report

Static analysis result for SHA-256 69cfad4e6ea5e830…

MALICIOUS

PDF

100.7 KB
MD5: bb9c59e090bb914963b7cd71ffad6fdc SHA-1: 8fce729c3ed4920242a4b85e2e688c280129bfb2 SHA-256: 69cfad4e6ea5e830e8d1cbda89482b8adefb59048e26e71d95a4ec52712b7449
108 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF file contains XFA (XML Forms Architecture) which is known to be vulnerable to exploits. The embedded JavaScript, although obfuscated, is designed to execute malicious code. ClamAV detection and ML classification strongly indicate malicious intent, likely involving the download and execution of a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded script payload in PDF stream low PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000246.bin
75acfba6772d99141a69c9b33106dfd75d2d23f2b897e2b084c793db4a12e9ac
pdf-embedded-script PDF raw stream script payload at offset 0x246 102347 bytes