Malicious PDF — malware analysis report

Static analysis result for SHA-256 86b4e9d2d9653d33…

MALICIOUS

PDF

111.7 KB
MD5: 857d279f279e569df5db15266001e6cc SHA-1: 93ebf2277b0a504b76f77053dde0efeaf037a74f SHA-256: 86b4e9d2d9653d331d6f4ff25b63e6c337c891b48937a1de96110fc39f2f81db
88 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File T1204.002 Malicious File: User Execution: Malicious PDF

The PDF file contains an embedded script payload and utilizes XFA forms, indicating a malicious intent. ClamAV detection as Pdf.Exploit.Agent-6136306-0 further confirms its malicious nature. The embedded script is likely responsible for delivering the exploit, though its exact function is obscured by the PDF structure. The embedded URLs are not directly indicative of malicious activity.

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_0000026a.bin
ee3537ae6e24689dc8c658261214c563ec92d34d8b7c76c59fca3f1c743c4ef1
pdf-embedded-script PDF raw stream script payload at offset 0x26A 113685 bytes