Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a4a38d873824cfd…

MALICIOUS

PDF

97.9 KB
MD5: 7fea1b4d3c20310d194b311a9b066b8d SHA-1: 4d5cb11b183104755680e78cd4dab827fc4d819f SHA-256: 2a4a38d873824cfd6dd682cbc1cefb40728ebeec803c051ccb4ab748f5e42e23
88 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1204.002 Malicious File

The PDF file contains an embedded script payload and triggers heuristics related to XFA forms, indicating it's designed to exploit vulnerabilities. ClamAV detection confirms its malicious nature, identifying it as Pdf.Exploit.Agent-6136306-0. The embedded script is likely responsible for downloading and executing a second-stage payload, though its exact functionality is obscured by the PDF structure.

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_0000026c.bin
eace499753fd09d27e7f06485ec523659e67bed73e5eabec4dea280ce4b1d133
pdf-embedded-script PDF raw stream script payload at offset 0x26C 99521 bytes