Malicious PDF — malware analysis report

Static analysis result for SHA-256 876452cdc8548821…

MALICIOUS

PDF

12.3 KB
MD5: 9bed38fc91644575216fe130d7699317 SHA-1: 39c4a52e242f402549b9061ef6ba6ff430f65222 SHA-256: 876452cdc8548821a4903bc1b7b4d2a0c89803c7173a07bb996062261ad049f0
116 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

This PDF file was flagged as malicious by ML classifiers and ClamAV, indicating it contains an exploit. The presence of an embedded script payload and an embedded file suggests the document is designed to execute arbitrary code, likely downloading a second-stage payload. The benign URLs present do not appear to be directly related to the malicious functionality.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • ClamAV: Pdf.Exploit.Dropped-78 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-78
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded script payload in PDF stream low PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0008.bin
5db5d7f00d45bcb49e9f992dd90a6feb10cae75ed45189619aeefcdcd3e30fbf
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0xC6 11829 bytes