Malicious PDF — malware analysis report

Static analysis result for SHA-256 d9e3c6306aed2f7f…

MALICIOUS

PDF

136.8 KB Created: 2011-09-08 05:03:17 Authoring application: FPDF 1.6
MD5: e991fbf7f88ad7823281c9dc1f385af5 SHA-1: d41b1fb24f008bac06bc4d5ebebe26c761f8589c SHA-256: d9e3c6306aed2f7feef9f6efff76f74c630e9197d4500df594dfafd411402c22
110 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing Attachment

The file is a PDF document identified as malicious by ML classification and ClamAV with the signature Pdf.Exploit.Agent-36874. The presence of XFA forms and AcroForm buttons suggests an attempt to exploit PDF vulnerabilities. The ML classifier's high confidence score further supports the malicious nature of the file, likely indicating it's a dropper for further malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-36874 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36874
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_001_off000008ed.bin
4ef6d4e20529f9d7215f75df605dbed98893e6dfb786bc7d529bf9af1e71f540
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8ED 1462 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).