Malicious PDF — malware analysis report

Static analysis result for SHA-256 e03b4f96db22070d…

MALICIOUS

PDF

23.0 KB
MD5: ed94c9a59f613b2266241e552d2e1268 SHA-1: 0dadba37e32174156d913d69a918ab8dbf1dc30f SHA-256: e03b4f96db22070d81eb4ea24b42b89e7d0941c352b249d99106ae76d0a171a9
66 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged as malicious by an ML classifier with high confidence. It contains an embedded script payload, indicating an attempt to execute malicious code. The presence of XFA form elements and embedded files further supports its malicious nature. The exact intent of the embedded script could not be determined due to its obfuscated nature, but it is likely designed to download and execute a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9979

Heuristics 4

  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_0000032a.bin
1eca43a43b953085bccdf74d5270ae79c2e62dcfc48e89bc6413a82daa081240
pdf-embedded-script PDF decompressed stream script payload at offset 0x32A 23519 bytes