Malicious PDF — malware analysis report

Static analysis result for SHA-256 3bc455d138846cfe…

MALICIOUS

PDF

121.2 KB
MD5: bdff086cbfd443f3d1af0a2d0d1f2dbc SHA-1: fb36c9e8e310cb405e885bea860a2e716fdc42e7 SHA-256: 3bc455d138846cfeeb29726e71335ff1d8057e695e17181b443d5cd840e7999e
100 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing Attachment

The PDF was flagged by ClamAV as Pdf.Exploit.Dropped-78 and a machine learning classifier indicated a high probability of maliciousness. The presence of an XFA form suggests an exploit targeting that functionality. An embedded URL was also extracted, likely used to download a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Dropped-78 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-78
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PSEOF. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/