Malicious PDF — malware analysis report

Static analysis result for SHA-256 10dc8151c7787c76…

MALICIOUS

PDF

31.9 KB
MD5: 8862b99690301264499c564034266cc4 SHA-1: e053f5ba8d10ffa1ede4011862fc7cd51f316e03 SHA-256: 10dc8151c7787c764128ebd21e7b245f5bec355ff200d3da0582e9c251828ee6
100 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment

The PDF was flagged by ML classifiers and ClamAV as malicious, specifically detecting embedded JavaScript and XFA form usage. The embedded URL, while seemingly benign, is part of the exploit chain. The presence of JavaScript indicates an attempt to execute malicious code, likely to download and run a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Js.Exploit.HTML-30 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Js.Exploit.HTML-30
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/