Malicious PDF — malware analysis report

Static analysis result for SHA-256 dc8e54be0622300e…

MALICIOUS

PDF

98.0 KB
MD5: 020018c1ee4ba4e054b717c523b9572f SHA-1: 1c4fc9f4c06ede2a67c804a8cc8c33604b08fbed SHA-256: dc8e54be0622300e129e86511ea3e47e6f37f715ab35a347aefe85d840a67e27
118 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution: Malicious File T1566.002 Phishing: Spearphishing Attachment

The file is identified as a malicious PDF by multiple heuristics, including a critical ClamAV detection and a high ML classifier score. The presence of an XFA form and an embedded script payload indicates an attempt to exploit PDF vulnerabilities. While the embedded script's exact function is not fully discernible due to obfuscation, its presence alongside the XFA structure strongly suggests it's used to download and execute a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_0000026a.bin
fb91b9622362d9eb6e61f5427d873933115d27c98e5400fb7833509499178767
pdf-embedded-script PDF raw stream script payload at offset 0x26A 99625 bytes