Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef4024ac0bebedd6…

MALICIOUS

PDF

136.8 KB Created: 2011-09-08 05:03:17 Authoring application: FPDF 1.6
MD5: 84802fa0529e2ee658e4367eb6ef0b24 SHA-1: 3479d678f287807c23a5f3302a0630dd20732bd9 SHA-256: ef4024ac0bebedd698022f38060ce34632c8ed0992f25a3daa6da289921a9b1e
78 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1204.002 Malicious File

The critical ClamAV heuristic firing indicates this PDF is recognized as a known exploit, specifically 'Pdf.Exploit.Agent-36874'. The presence of XFA forms and AcroForm buttons further suggests the potential for exploiting interactive elements within the PDF. While no specific script was extracted, the combination of these factors strongly points to a malicious PDF designed to exploit a vulnerability.

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-36874 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36874
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_001_off000008ed.bin
3e242eff3ab242c97fdd6075adc76a32c8036624d34d1c4dcd130b5390a867e6
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8ED 1490 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).