Malicious PDF — malware analysis report

Static analysis result for SHA-256 92be2c1cdc08f322…

MALICIOUS

PDF

7.2 KB Created: 2012-04-21 19:58:55
MD5: 3c579a3771284dc504e2cb7c14982c2b SHA-1: a953696a8717cbd83c20e51055c5e79ca3cd1a17 SHA-256: 92be2c1cdc08f322a9be541381926eb6cc5fb4f66f0a3f19d5ba46ae7564b2a4
98 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File T1204.002 Malicious File: User Execution

The critical ClamAV detection 'Pdf.Exploit.Dropped-156969-1' strongly indicates this PDF is malicious. The 'PDF_EMBEDDED_SCRIPT_PAYLOAD' heuristic confirms the presence of an embedded script, likely responsible for dropping the malicious payload. The document body's content is nonsensical and truncated, suggesting it's either obfuscated or irrelevant to the exploit.

Heuristics 5

  • ClamAV: Pdf.Exploit.Dropped-156969-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-156969-1
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0006.bin
a7255dba6e8c0017d7c5b330a0e2a63eb7b66b2f8f8cfe41764b3f8833feee48
pdf-embedded-file PDF EmbeddedFile object 6 at offset 0x9D0 7172 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 4 long base64-like blob(s).