Malicious PDF — malware analysis report

Static analysis result for SHA-256 be0a552cf48e4abf…

MALICIOUS

PDF

809.3 KB First seen: 2026-05-04
MD5: 37a9c45b78f4dee9da8fd8019f66005a SHA-1: 28575e005666e31419ecbfa6a65699c96f1d0568 SHA-256: be0a552cf48e4abf95678e14b63e4c0d334034294252629173493167702cdd60
136 Risk Score

🔏 Digital signature Signature invalid

A signature covers the whole signed byte range — PDF JavaScript is never signed on its own — and does not by itself mean the document is safe.

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The critical ClamAV detection and the ML classifier strongly indicate malicious intent. The presence of embedded JavaScript, identified by heuristic firings, suggests the PDF is designed to act as a dropper. This JavaScript is likely responsible for downloading and executing a second-stage payload, which is a common technique for malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 6

  • ClamAV: Pdf.Dropper.Agent-7142700-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7142700-0
  • PDF digital signature is cryptographically invalid medium PDF_SIGNATURE_INVALID
    A signature's CMS failed verification: either the signer's signature over the signed attributes is invalid, or the signed content digest does not match the bytes the ByteRange covers. The signature was tampered with, forged, or the signed content was altered.
  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/ Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xci/3.0/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-template/2.8/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-data/1.0/'/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-data/1.0/Referenced by PDF JavaScript

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_000_off0006d90c.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6D90C 289498 bytes
SHA-256: dcefc16710d335e69f60cdd8a0e174d43939d02eaa8dd4c6d7ce4ca63f06495b