Malicious PDF — malware analysis report

Static analysis result for SHA-256 caab539f36e860f1…

MALICIOUS

PDF

11.9 KB
MD5: 953f3d8c4e657c0a0ca0ec03cca1c760 SHA-1: 3332d896c03cb7f401ead4a8cbb0db84eccb6066 SHA-256: caab539f36e860f14ff85e27a6ba3e6fb8abdb775883f61997302c033e68388a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV with the signature Pdf.Exploit.Dropped-78, indicating it exploits a known PDF vulnerability. The presence of an embedded script payload and an embedded file further supports this. The exact nature of the exploit and payload is not fully discernible from the provided heuristics and limited document body content.

Heuristics 5

  • ClamAV: Pdf.Exploit.Dropped-78 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-78
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0008.bin
d7dcc143af62d9d710156215530893812ea8e002c5dd6384d2b37c8fc753a237
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0xC6 11394 bytes