Malicious PDF — malware analysis report

Static analysis result for SHA-256 98a7fa2aa5c77b56…

MALICIOUS

PDF

27.3 KB
MD5: e8329043d1255c3244e36ce8f2533b77 SHA-1: 3e82128856000f7d6fc5653b3573a291e5467ead SHA-256: 98a7fa2aa5c77b565431ed852bebbfacc4e527fbbc32b9ac938bebfa3746c1fc
128 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing Attachment

The file is a PDF identified as malicious by ClamAV with the signature Pdf.Exploit.Dropped-78. High confidence is derived from the ML classifier output and the critical ClamAV detection. The PDF contains an embedded script payload, indicating it's designed to exploit vulnerabilities and drop further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • ClamAV: Pdf.Exploit.Dropped-78 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-78
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0008.bin
f19eb3d7261e1ce3d19842ee984bb9efbd89d7031431cd21ad56b65526553344
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0xC8 27210 bytes