Malicious PDF — malware analysis report

Static analysis result for SHA-256 b94c3da2c1a0e8a9…

MALICIOUS

PDF

42.6 KB
MD5: 65ee889a78a19bfdba3175098fa2452e SHA-1: 54c307d945253cbd948926c61e852e6c1e5aef71 SHA-256: b94c3da2c1a0e8a976fe17b4a95d0ace4ae4f07dd1cc5d36a42af2d4a4e2bdab
156 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.001 Spearphishing Attachment

The critical ClamAV detection indicates this PDF exploits a known vulnerability, likely to download and execute a secondary payload. Multiple embedded files were extracted, one of which is significantly larger than the others and may contain the primary exploit or payload. The XFA form and embedded script heuristics further support the exploitation vector.

Heuristics 6

  • ClamAV: Pdf.Exploit.Agent-36830 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36830
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/1.0/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0008.bin
0a2224c4023b216235b61c3fc4dd17bbfac1ab23a545687f51b97604cf654712
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0xC6 46 bytes
embedded_file_obj0009.bin
85174f17ac92e6adba5f428f4c8053c2f298f6063e8730bbdb908ce4bd728260
pdf-embedded-file PDF EmbeddedFile object 9 at offset 0x13C 689 bytes
embedded_file_obj0010.bin
69650a61091a018036679a3439cc6a018b6a91ebe9e0e3a6b36ceb04d6491a4f
pdf-embedded-file PDF EmbeddedFile object 10 at offset 0x438 160 bytes
embedded_file_obj0011.bin
0d1781c60a222373802ae509f2b418196bff61961c2ac14f76acea947871e001
pdf-embedded-file PDF EmbeddedFile object 11 at offset 0x523 454 bytes
embedded_file_obj0012.bin
d2f06f3fc6900856fe613a64a561919c8454dcbe0fdf238fb8b43e07016955ea
pdf-embedded-file PDF EmbeddedFile object 12 at offset 0x734 190 bytes
embedded_file_obj0014.bin
88f12313854f8d9b3ea6f7be9f15cd6dc65c4b5fbdd3d902f2d75627143e5645
pdf-embedded-file PDF EmbeddedFile object 14 at offset 0x83F 40857 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36830
Obfuscation or payload: unlikely