Malicious PDF — malware analysis report

Static analysis result for SHA-256 93d357213342d2c9…

MALICIOUS

PDF

136.8 KB Created: 2011-09-08 05:03:17 Authoring application: FPDF 1.6
MD5: 76ed7df95694face25aeb541764f7b95 SHA-1: e634d0a775bf9f95b8779629f16364ee2b5a6754 SHA-256: 93d357213342d2c9154c9520e86d5b71dfb01674e03604908a5df0235964a19f
78 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1059 Command and Scripting Interpreter

The critical ClamAV heuristic 'Pdf.Exploit.Agent-36874' strongly indicates a known PDF exploit. The presence of an XFA form and an AcroForm button with an action trigger further supports the exploitation of PDF features for malicious purposes. The embedded artifact suggests a secondary payload, common in exploit-based attacks.

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-36874 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36874
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_001_off000008ed.bin
cd856541eacd0f53c27ea78f9aa4d5996286fb50123e4e8e71f6faf993c2b205
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8ED 1470 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).