Malicious PDF — malware analysis report

Static analysis result for SHA-256 ce9fc2e0b031fe7c…

MALICIOUS

PDF

14.6 KB
MD5: e07f2740b9c26b67e604c04dd7cc1083 SHA-1: 3dcf3e1debce9d59ffb23ac1fbaf0191f13d5f2e SHA-256: ce9fc2e0b031fe7c30a71bd1bd67e202d57650e9c293d2f71b6a337a3695e00c
180 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing Attachment

The PDF utilizes XFA forms and contains an embedded script payload, as indicated by multiple high-severity heuristics. ClamAV detections for 'Pdf.Exploit.Dropped-78' and 'Pdf.Exploit.Agent-36809' on the main file and an extracted artifact confirm its malicious nature. The ML classifier also strongly flagged this PDF as malicious. The embedded script is likely responsible for dropping the secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • ClamAV: Pdf.Exploit.Dropped-78 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-78
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000329.bin
6f66b2a132e7013f4dc119280d7e20945c89d25659409f5bea37ce73523df7ef
pdf-embedded-script PDF raw stream script payload at offset 0x329 14250 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36809
Obfuscation or payload: unlikely