Malicious PDF — malware analysis report

Static analysis result for SHA-256 df5e3eda9e8bb370…

MALICIOUS

PDF

25.9 KB
MD5: 9196fee9df4a6801db37f3a2cb586d1c SHA-1: 3510e6cfd8e70dd834cc215d547ac2928469e633 SHA-256: df5e3eda9e8bb370dabf740402abcc76378b56e04eb079330e2d59ccce583c23
96 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing Attachment

The critical ClamAV heuristic indicates this PDF is detected as Pdf.Exploit.Dropped-78, suggesting it exploits known vulnerabilities. The presence of an embedded script payload further supports its malicious nature. While specific URLs were extracted, they were classified as benign or unknown, and no document body text was available for content analysis. The embedded file artifact also points to a dropped payload.

Heuristics 5

  • ClamAV: Pdf.Exploit.Dropped-78 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-78
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0008.bin
989a29e52a84828ad831009d824846ca867b4c9081459cacad6a23542aea6a2a
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0xC8 25760 bytes