Malicious PDF — malware analysis report

Static analysis result for SHA-256 eb0add8f3ed2871a…

MALICIOUS

PDF

79.2 KB
MD5: 66417f93568744aff4db321219e1750b SHA-1: e3ab0c56a5802e1da08c6d04c529f4f1fd9ee684 SHA-256: eb0add8f3ed2871af61d63de50f78b3c0c8b4d7011d683e1c0b62ca0f6f5d69f
148 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File T1204.002 Malicious File: User Execution

The PDF file contains an XFA form and an embedded script payload, triggering critical ClamAV detections for PDF exploits. The embedded artifact is also flagged by ClamAV. The presence of XFA and embedded scripts strongly suggests an exploit designed to execute malicious code upon opening.

Heuristics 5

  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_0000023e.bin
fa8a7dca88d15bd10624615b355ea03bf249a02d0fddb78e0a4a9413356fdbf2
pdf-embedded-script PDF raw stream script payload at offset 0x23E 80381 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36769
Obfuscation or payload: unlikely