Malicious PDF — malware analysis report

Static analysis result for SHA-256 7a3c39c8de3fcfb3…

MALICIOUS

PDF

101.2 KB
MD5: 4d01738df2215ecf47fae310a437d7f4 SHA-1: 4d6d7fa6d8b6472f96365547c41a0cfa8b8ddbdf SHA-256: 7a3c39c8de3fcfb35227cc447d86d91c4e86284fa9a2f91a20c14a97a0167ff8
88 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains an embedded script payload, as indicated by the PDF_EMBEDDED_SCRIPT_PAYLOAD heuristic. ClamAV also detected it as Pdf.Exploit.Agent-6136306-0. The embedded script is likely responsible for exploiting vulnerabilities within the PDF viewer to execute malicious code. The XFA form heuristic suggests the exploit may target XFA forms. The exact nature of the script's payload could not be determined due to obfuscation.

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000246.bin
49af27ea0aa110d46ec3db8a4e09b4a26931517b8104c75834b6a5ca6d4031ed
pdf-embedded-script PDF raw stream script payload at offset 0x246 102905 bytes