Malicious PDF — malware analysis report

Static analysis result for SHA-256 48c20f7eaaec1de4…

MALICIOUS

PDF

96.9 KB
MD5: 933979b9ead2efd5fdf0752a09c85e09 SHA-1: 5f255d46b5f0b6a53f594a4d3cfe183ecde3af03 SHA-256: 48c20f7eaaec1de46f769fadb60ff8a0854d8fab1e87db7231bff5ad63045851
88 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1059.001 PowerShell

The PDF file contains an embedded script payload and triggers heuristics related to XFA forms and embedded scripts, indicating it's designed to exploit vulnerabilities. ClamAV detection confirms its malicious nature. The embedded script is likely responsible for downloading and executing a second-stage payload, though its exact functionality is obscured.

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_0000026c.bin
173dd5f4a78f6d2fc3606be8d67fe3f9e11e7c8bbd252b08e72aaeb6cfc4a06d
pdf-embedded-script PDF raw stream script payload at offset 0x26C 98547 bytes