Malicious PDF — malware analysis report

Static analysis result for SHA-256 75804432cc160315…

MALICIOUS

PDF

101.9 KB
MD5: 9ea99139f7ca2951abef9ddabf896f6b SHA-1: 6d01859c14485c6b4284f82f4a85083f3ae5ef7a SHA-256: 75804432cc160315868e04809ee66818d25a44951ffaef9b8ca4a4a885089479
108 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF file contains an XFA form with embedded JavaScript, flagged by multiple heuristics as malicious. The JavaScript appears to be obfuscated and attempts to download and execute a payload. The presence of XFA and embedded scripts strongly suggests an exploit targeting PDF viewers, likely delivered as a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded script payload in PDF stream low PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000246.bin
c9321f1642d11ac7e63c5549f650abb9f2bf0431de03f911072d975a8bbf5c0a
pdf-embedded-script PDF raw stream script payload at offset 0x246 103581 bytes