Malicious PDF — malware analysis report

Static analysis result for SHA-256 d2e05954164cdfc6…

MALICIOUS

PDF

79.3 KB
MD5: d8cdaf171978dbf6ef88d7ec0aecb1a0 SHA-1: 0a4e2097ca785bef8960100448a4ad536a390e26 SHA-256: d2e05954164cdfc64ac35f52e7a216e26ef94898389f8b08a0a2b5f593b20da4
178 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1204.002 Malicious Link: Malicious File

Static analysis identified this PDF as malicious, with critical detections from ClamAV (Pdf.Exploit.Agent-6136306-0) and a high ML classifier score. The presence of an XFA form and an embedded script payload indicates an exploit attempt. While no specific script content was provided for detailed analysis, the overall indicators point to a malicious PDF designed to exploit vulnerabilities or trick the user into executing a payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_0000023e.bin
fc258d65837fd808ebd7c247bc2e72362bc2a86d10067bd8890fbb1fe38606b3
pdf-embedded-script PDF raw stream script payload at offset 0x23E 80469 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36769
Obfuscation or payload: unlikely