Malicious PDF — malware analysis report

Static analysis result for SHA-256 ab58a9e726754e1d…

MALICIOUS

PDF

12.0 KB
MD5: 9424203d87831353b3b94a127cfe556a SHA-1: 99d4276eb884a364a7edaac5cc5d5935f8992bb5 SHA-256: ab58a9e726754e1dea8e72f17bf116e5a8d3bee9dd6c92757a27c5cd4de1f552
96 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing Attachment

The PDF file was detected by ClamAV as Pdf.Exploit.Dropped-78, indicating it is a known exploit dropper. Static analysis revealed embedded content and a script payload within a PDF stream, suggesting the file is designed to execute malicious code. The embedded file artifact further supports the payload delivery mechanism. The benign and unknown URLs do not appear to be directly involved in the malicious activity.

Heuristics 5

  • ClamAV: Pdf.Exploit.Dropped-78 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-78
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0008.bin
0e271815f9fdd64e92c08ea7721d7ad19bf825aee16133144cd10e23a1664669
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0xC8 11571 bytes