Malicious PDF — malware analysis report

Static analysis result for SHA-256 9929461da08eeba5…

MALICIOUS

PDF

50.9 KB
MD5: ef2ec1ec70123ca2cdaa64a3ee7692bd SHA-1: ad50c6954df8a834d9467a679a49f5196893a7df SHA-256: 9929461da08eeba596bbb89672a0d76772363263ef9a946c971005f31c44b373
118 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF was flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Exploit.Agent-6136306-0' and a high ML score, indicating malicious intent. The presence of an embedded script payload within an XFA form suggests an exploit is being delivered. While the document body contains garbled text, the overall structure and heuristic firings point to a malicious PDF designed to exploit vulnerabilities.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000240.bin
f06f2cd78e4d388e3ed79f84a606f5f3b9a5e39d07474881a6a6150e78a1693f
pdf-embedded-script PDF raw stream script payload at offset 0x240 51380 bytes