Malicious PDF — malware analysis report

Static analysis result for SHA-256 a8a72114e80a7d30…

MALICIOUS

PDF

100.5 KB
MD5: 46e79cc5c05f4244b39e1dc3a9fcfd90 SHA-1: 61f0d38d72525b335cd179e03664f197d5d438ee SHA-256: a8a72114e80a7d3073872b18564a15765d0423186f5fdfa55b233d8bfd9354d6
88 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains an XFA form and an embedded script payload, indicating it is designed to exploit vulnerabilities. ClamAV detected this as Pdf.Exploit.Agent-6136306-0. The embedded script is likely responsible for delivering the malicious payload, although its exact function is obscured by the PDF stream.

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000246.bin
92448ad326049856d997f38475fecaf3b3fac517cf98b07fc511c4d4cd7b11b7
pdf-embedded-script PDF raw stream script payload at offset 0x246 102152 bytes