Malicious PDF — malware analysis report

Static analysis result for SHA-256 841a0f98f4fa07a7…

MALICIOUS

PDF

45.5 KB
MD5: 37b2fdb17af07c4aec25ef641cb594fc SHA-1: 1b8766808196c347d15cad7bbb473b90869cb387 SHA-256: 841a0f98f4fa07a730dee4fcf56359402cc66bc09b9e07deb111f0c26db8dbfc
114 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file was flagged by multiple heuristics as malicious, including a critical ClamAV detection for 'Pdf.Dropper.Agent-1507081' and a high ML score. Embedded JavaScript actions and streams were detected, indicating the file's intent to execute code. The presence of XFA form elements further supports the likelihood of complex, potentially malicious, scripting. The primary function appears to be that of a dropper, designed to download and execute additional malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9952

Heuristics 5

  • ClamAV: Pdf.Dropper.Agent-1507081 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-1507081
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
c214d526ef52013fa04ef28a129fe5a93f2077799159b49a9addd053e8384316
pdf-javascript-stream PDF /JS object 12 at offset 0xA1ED 3910 bytes