Malicious PDF — malware analysis report

Static analysis result for SHA-256 8c9050e4d9a1721d…

MALICIOUS

PDF

79.1 KB
MD5: ea7425b89c0f85cbaf8ae827b2347f7e SHA-1: 710fd84f7c991ebb8980f5d125be1344ecbae1e5 SHA-256: 8c9050e4d9a1721dd65ead4fa5dccb91f8b7813acbea5f83e7f6d10d09b362c5
180 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains an embedded script payload and triggers critical ClamAV detections for PDF exploits and embedded JavaScript exploits. The ML classifier also flagged it with high confidence. The embedded script is likely responsible for downloading and executing a second-stage payload, as indicated by the 'Js.Exploit.HTML-29' detection on an extracted artifact. The XFA form structure is also noted.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_0000023c.bin
09792ae6b021686978261f385474debd4710e6356636096daf5cb1fcae3ee2b0
pdf-embedded-script PDF raw stream script payload at offset 0x23C 80283 bytes
Detection
ClamAV: Js.Exploit.HTML-29
Obfuscation or payload: unlikely