Malicious PDF — malware analysis report

Static analysis result for SHA-256 ae9e3f58ee89adad…

MALICIOUS

PDF

14.6 KB
MD5: bc22572d3b07c26139a19fe09ae4fa36 SHA-1: e486cb4c14365da6da1d32d29e6eb1ecafab0ff5 SHA-256: ae9e3f58ee89adadf2ceb1f1fcc26b0b19d6f295c1094d875b73e2d04e4a749b
178 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1059.001 PowerShell

The PDF was flagged by multiple high-confidence heuristics, including ML classification and ClamAV detections indicating exploit and dropped payloads. The presence of an embedded script payload suggests it is designed to download and execute further malicious content. The embedded URL is likely part of the exploit chain.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • ClamAV: Pdf.Exploit.Dropped-78 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-78
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000329.bin
138bb055072089a31f6e921567f7448fef3d5bb4e8110446459c435fd8d838b7
pdf-embedded-script PDF raw stream script payload at offset 0x329 14217 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36809
Obfuscation or payload: unlikely