Malicious PDF — malware analysis report

Static analysis result for SHA-256 a934f8d2cb2ff245…

MALICIOUS

PDF

136.8 KB Created: 2011-09-08 05:03:17 Authoring application: FPDF 1.6
MD5: e344c2620d7f89cefb45ecb258592f76 SHA-1: be24ebb706f020d0f0f7afeb9c5d0bc088d170cf SHA-256: a934f8d2cb2ff24563bba8e2591af61e48e53bcd7513092f35dd0d8d05a4bb12
110 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File T1204.002 Malicious File: User Execution: Malicious File

The file is a PDF document flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Exploit.Agent-36874'. The ML classifier also strongly indicates maliciousness. The presence of XFA forms and AcroForm buttons suggests an attempt to leverage PDF features for exploitation. The extracted document body text is heavily garbled, indicating potential obfuscation or corruption, further supporting a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-36874 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36874
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_001_off000008ed.bin
ea4861ab02b9ce67a84e548a3148c6924105d0e10576bcc4290dd7a211f99997
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8ED 1462 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).