Malicious PDF — malware analysis report

Static analysis result for SHA-256 48f9c668498a68c3…

MALICIOUS

PDF

100.5 KB
MD5: 5e5def7ef3d29b3b82639f7e31f9f58a SHA-1: c6cc9e7fbb8eddc6bd232105dbb2c96f1819c539 SHA-256: 48f9c668498a68c3447a5e88584ce3ecdd91d3bc46560fcc5c8822f33d409c4c
148 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains an embedded script payload and utilizes XFA forms, indicating an exploit attempt. ClamAV detections further confirm its malicious nature. The embedded script is likely responsible for downloading and executing a secondary payload, as suggested by the heuristic firings and the nature of XFA-based exploits. The URLs present are related to XFA schemas and Adobe, but their reputation is unknown or benign, so they are not considered primary IOCs.

Heuristics 5

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000246.bin
6c8c0928e1eab8a91372626a55d64f6734ef82b7b993ff37037d37df0e164699
pdf-embedded-script PDF raw stream script payload at offset 0x246 102156 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36769
Obfuscation or payload: unlikely