Malicious PDF — malware analysis report

Static analysis result for SHA-256 efa186c30dfd2eb3…

MALICIOUS

PDF

46.4 KB
MD5: 8cd515e80d56ea8d106e7299607e3d1d SHA-1: 07dcb4d7c3b79b7303fa2c76ea38ac763c0476be SHA-256: efa186c30dfd2eb369ea4a00f5ec0b6e8aea36fa0105249aa7150f8019c50d17
68 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.001 Spearphishing Attachment

The PDF file contains an XFA form, which is a known vector for exploitation. ClamAV detected this file as Pdf.Exploit.Dropped-78, indicating it's a dropper for further malicious payloads. An embedded URL was also found, likely used to download the secondary stage. The XFA structure and embedded URL strongly suggest a malicious intent to exploit vulnerabilities and download additional malware.

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-78 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-78
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/