Malicious PDF — malware analysis report

Static analysis result for SHA-256 bc8d8cd888a9b072…

MALICIOUS

PDF

97.4 KB
MD5: 13cee5c200b67f2e993d6f0b332e5e24 SHA-1: cb61366343b1ba332977710b173439adaafe53fe SHA-256: bc8d8cd888a9b0726fc9bca085a3d26d2a98c1f07923fac8d084d4f9bee93df8
118 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains an embedded script payload and triggers XFA form heuristics, indicating an exploit attempt. ML classification and ClamAV detection confirm its malicious nature. The embedded script is likely responsible for downloading and executing a second-stage payload, as suggested by the PDF_EMBEDDED_SCRIPT_PAYLOAD heuristic.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_0000026c.bin
a5cacc32b1bdb1341e3581f76f16331024ac24a220f7d5de9e84b470727e9d82
pdf-embedded-script PDF raw stream script payload at offset 0x26C 98981 bytes