Malicious PDF — malware analysis report

Static analysis result for SHA-256 46a867db9f345678…

MALICIOUS

PDF

18.3 KB
MD5: 91cb73286b050ec20bd9ac6b9b569b84 SHA-1: be46414993d71574daab85f5ce7fb7ee2295fe35 SHA-256: 46a867db9f345678363c3728d870e2242f051b494e085d8ee95a34d46398197d
148 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains an embedded script payload and triggers heuristics related to XFA forms and embedded scripts, indicating it's designed to exploit vulnerabilities. ClamAV detections further confirm its malicious nature. The embedded URL is likely part of the exploit chain.

Heuristics 5

  • ClamAV: Pdf.Exploit.Agent-36789 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36789
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.x&#102;a.org/schema/xfa-template/2.5/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000325.bin
07f0815d42502062679e471c2b760d52980d484df2fd21e7d227b88f90b70032
pdf-embedded-script PDF raw stream script payload at offset 0x325 18067 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36809
Obfuscation or payload: unlikely