Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd04843160e1e00e…

MALICIOUS

PDF

97.0 KB
MD5: c6b57df157831ef45ca5c9bab1644a84 SHA-1: abe8b0f1d99e2704673f636873e19bdfa449d5da SHA-256: fd04843160e1e00eddc49ac8daed6e9e43ff0fbe4c206e6c3c189097c38be1a1
118 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1059.001 PowerShell

The PDF exhibits characteristics of malicious intent, including the presence of an XFA form and an embedded script payload. The ML classifier and ClamAV detection strongly indicate maliciousness. The embedded script, though not fully detailed, is likely responsible for downloading and executing a secondary payload, a common technique for initial access and further compromise. The document body content is not indicative of a specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_0000026c.bin
91fed6825b709384056b90238b7f947e95edf1e08e05e786487cbe6acea34f70
pdf-embedded-script PDF raw stream script payload at offset 0x26C 98653 bytes