Malicious PDF — malware analysis report

Static analysis result for SHA-256 52edd31b147f5455…

MALICIOUS

PDF

100.5 KB
MD5: 3fb1c388d5fca0e694e24b28523ccd15 SHA-1: af4f75075069de4c3764ac240c5d3a629e1ba42f SHA-256: 52edd31b147f545510d562db8aa9d9cf6ea4894af3ecb2698ae50e15a8cd3bab
148 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution: Malicious PDF T1059.001 Command and Scripting Interpreter: PowerShell

The PDF utilizes XFA forms, a known vector for exploiting vulnerabilities. ClamAV detections indicate the presence of a malicious exploit agent. The embedded script payload, though not fully detailed, is the likely mechanism for delivering the exploit. The embedded URLs are related to XFA and Adobe, but their specific role in the exploit is unclear.

Heuristics 5

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000246.bin
9ee009cdc7a1403f77a732961641a475b9d5b5b1448729b8ff008342843b8344
pdf-embedded-script PDF raw stream script payload at offset 0x246 102156 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36769
Obfuscation or payload: unlikely