Malicious PDF — malware analysis report

Static analysis result for SHA-256 34e5057e630c5e54…

MALICIOUS

PDF

121.5 KB
MD5: 021ff921312641ea62ad1bc8c2741f2b SHA-1: e82946150d593e13eb8d105429c1203443511464 SHA-256: 34e5057e630c5e549805455c11b5406dc34b2a3e97bbe8ae99f9d191b3a80398
98 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution: Malicious PDF

The PDF was flagged by multiple heuristics, including a critical ClamAV detection for Pdf.Exploit.Dropped-78 and an ML classifier indicating high maliciousness. The presence of an XFA form suggests an exploit targeting that functionality. The embedded URL, while seemingly benign, is part of the PDF structure and could be used in conjunction with the exploit.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-78 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-78
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/