Malicious PDF — malware analysis report

Static analysis result for SHA-256 229d0fbec4046a9a…

MALICIOUS

PDF

100.7 KB
MD5: 4ce82d7d5b0082d5bb2ac86fb9b4af9f SHA-1: 46e558d454d771eee03807620f25fae0a6d25ac3 SHA-256: 229d0fbec4046a9abe91c015a30c68bd5d712f09118186556a4663a2b1111dad
88 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File T1204.002 Malicious File: User Execution: Malicious Attachment

The critical ClamAV heuristic 'Pdf.Exploit.Agent-6136306-0' strongly indicates a known PDF exploit. The presence of an embedded script payload and XFA form further supports this, suggesting the PDF is designed to execute malicious code upon opening. The embedded script is too large and complex to analyze statically, but its presence is a key indicator of a downloader or exploit delivery mechanism.

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000246.bin
6a4326f5a4fef1bf2e86805e98c816ae1ba16798b4acfcb0276c4bd053e8814d
pdf-embedded-script PDF raw stream script payload at offset 0x246 102347 bytes