Malicious PDF — malware analysis report

Static analysis result for SHA-256 c172d351c0e16e04…

MALICIOUS

PDF

101.9 KB
MD5: 7dbb728b80cf1a583b8c240b91a694cf SHA-1: f0cb077951909287098ef46a51cfd7d54b81017e SHA-256: c172d351c0e16e04dd4484535ddaaa4b56f048148b87e4c5128b342b3368724b
88 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1059.007 JavaScript

The file is identified as a malicious PDF by ClamAV, specifically 'Pdf.Exploit.Agent-6136306-0'. Static analysis detected an XFA form and an embedded script payload within a PDF stream. The embedded script is likely responsible for executing the malicious payload, although its exact function is obscured by the PDF structure. The presence of XFA forms and embedded scripts is a common delivery mechanism for PDF-based exploits.

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000246.bin
9495176535074798497f9356cddb982531bed7041e6eba20176c98f5183373d3
pdf-embedded-script PDF raw stream script payload at offset 0x246 103573 bytes