Malicious PDF — malware analysis report

Static analysis result for SHA-256 b669b9b234351789…

MALICIOUS

PDF

3.4 KB
MD5: 3d77fe31dc22795bfe78dcfab090f6bf SHA-1: f6c0063e5478d56e9bd26b6b186f3d606c128201 SHA-256: b669b9b23435178999cadecee1ecc34ba6f681502e67e23985117f804f1ff360
158 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File T1566.001 Spearphishing Attachment

This PDF document exhibits high-risk heuristics related to XFA forms and the use of eval() and unescape() functions, indicating script execution. An embedded script payload was detected, and a suspicious file 'embedded_file_obj0010.bin' was extracted. The combination of these factors strongly suggests the document is designed to deliver a secondary malicious payload.

Heuristics 7

  • XFA form contains risky executable script high CVE related PDF_XFA_SCRIPT
    PDF embeds an XFA form whose script block contains exploit, submission/launch, or shell-execution primitives. Ordinary LiveCycle print/update scripts are left as generic XFA/JS signals unless stronger behavior is present.
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • unescape() call high PDF_UNESCAPE
    unescape() found — often used to decode shellcode in PDF JS exploits (matched inside decoded stream)
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 7

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0008.bin
ef62e46517e0ab9128be5d63feaf817466470f1173e71e6b58c21218c5c2f3c8
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0x346 47 bytes
embedded_file_obj0009.bin
101ba7115e4b42f8f582812aa8c52e1372a145b22f143ddc24dfad027378eef6
pdf-embedded-file PDF EmbeddedFile object 9 at offset 0x3D2 229 bytes
embedded_file_obj0010.bin
00cdc72b3f69d01c30cb2bbd5f85e9576f3c7c2b8064626d1a3146f3507cfd16
pdf-embedded-file PDF EmbeddedFile object 10 at offset 0x4C4 1722 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s).
embedded_file_obj0011.bin
e1c68077d11dccab0579be0ccb04561b7f732fa1883680eef6e55b9e9477fe22
pdf-embedded-file PDF EmbeddedFile object 11 at offset 0x7A3 200 bytes
embedded_file_obj0012.bin
741b90059b0e9f50c02f9e0c6b356036cf2b92601b083d5b342090f958020764
pdf-embedded-file PDF EmbeddedFile object 12 at offset 0x895 120 bytes
embedded_file_obj0013.bin
863fe193664516f0db42fd686d863a1b9cad88d3d0cb37f8d2f8497979368f02
pdf-embedded-file PDF EmbeddedFile object 13 at offset 0x94D 78 bytes
embedded_file_obj0014.bin
92a3ce61d783e15932b5de127ce45a9b4c2f98f4da2453f65241573c1dda808a
pdf-embedded-file PDF EmbeddedFile object 14 at offset 0x9F5 56 bytes