Malicious PDF — malware analysis report

Static analysis result for SHA-256 8cd6a7977a221458…

MALICIOUS

PDF

100.5 KB
MD5: 233566c5efbe3e89b9f79aae93dc4b5c SHA-1: 722e163841cf67b4b200e46ff6eeb5fc5c77b9e9 SHA-256: 8cd6a7977a221458ea2e5b7f45ab6367a2ec0e82aceabc7795628cc863461563
120 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file was flagged by multiple heuristics, including a critical ClamAV detection (Pdf.Exploit.Agent-6136306-0) and a high ML classifier score, indicating malicious intent. The presence of an XFA form and an embedded script payload suggests the file is designed to exploit vulnerabilities or execute malicious code upon opening. The embedded script is likely responsible for downloading and executing a second-stage payload, although its exact functionality is obscured by the PDF structure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000246.bin
7fc85ed6b49628b453e9036289ffd4f7fdad807154cdb3451a30481f92b37e50
pdf-embedded-script PDF raw stream script payload at offset 0x246 102152 bytes