MALICIOUS
68
Risk Score
Malware Insights
MITRE ATT&CK
T1059.007 JavaScript
T1204.002 Malicious File
The PDF file contains an XFA form, which is a known vector for exploits. ClamAV detected this file as Js.Exploit.HTML-30, indicating a JavaScript exploit is present. The embedded URL likely hosts the malicious payload or is part of the exploit chain.
Heuristics 2
-
ClamAV: Js.Exploit.HTML-30 critical CLAMAV_DETECTIONClamAV detected this file as malware: Js.Exploit.HTML-30
-
XFA form low PDF_XFAPDF uses XML Forms Architecture — can contain script logic
Open this report in the interactive analyzer, or submit your own file for analysis.