Malicious PDF — malware analysis report

Static analysis result for SHA-256 d4fe4edc877cba7e…

MALICIOUS

PDF

42.4 KB
MD5: 4241b232894ff6af73a0d0632a885cf3 SHA-1: 23b27282e8c447934c9ac3bce1bdb0092e0ad301 SHA-256: d4fe4edc877cba7e8f044d089b519eaa449a2ca6edd14f3818275c1cd876f222
156 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File T1204.002 Malicious File: User Execution

The file is identified as a malicious PDF by ClamAV with the signature Pdf.Exploit.Agent-36830. Static analysis revealed embedded script payloads and embedded files, indicating the PDF is designed to exploit vulnerabilities and deliver further malicious content. The presence of XFA forms and embedded files strongly suggests an exploit delivery mechanism.

Heuristics 6

  • ClamAV: Pdf.Exploit.Agent-36830 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36830
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/1.0/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0008.bin
0a2224c4023b216235b61c3fc4dd17bbfac1ab23a545687f51b97604cf654712
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0xC6 46 bytes
embedded_file_obj0009.bin
12dac8c41cd7df921de7bc1b269a54f60ea0c60d7d0949729dc5c1e779c00e38
pdf-embedded-file PDF EmbeddedFile object 9 at offset 0x13C 689 bytes
embedded_file_obj0010.bin
8259db878f85521b2ee9c7ec108d34b19d3b6c900af7d501b5135c2cd3dcfde6
pdf-embedded-file PDF EmbeddedFile object 10 at offset 0x438 168 bytes
embedded_file_obj0011.bin
ab4fcddbe28967b6da4c2cfc919dcc0cdcf7fbaae64bc14d7207af4454e8ae2d
pdf-embedded-file PDF EmbeddedFile object 11 at offset 0x52B 442 bytes
embedded_file_obj0012.bin
d2f06f3fc6900856fe613a64a561919c8454dcbe0fdf238fb8b43e07016955ea
pdf-embedded-file PDF EmbeddedFile object 12 at offset 0x730 190 bytes
embedded_file_obj0014.bin
2ec14cd57ef588697b6351024ca015d3ca91a5cbf4f4c6989c2f9f237511008f
pdf-embedded-file PDF EmbeddedFile object 14 at offset 0x83B 40651 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36830
Obfuscation or payload: unlikely