Malicious PDF — malware analysis report

Static analysis result for SHA-256 8e51be20f92b652d…

MALICIOUS

PDF

28.0 KB
MD5: bccb32eb8989d8f4c62f85f6a5669abf SHA-1: baf138eaa82e2f6f58f6fb86bd2be8014cf21c2b SHA-256: 8e51be20f92b652d981308b35ce7186b2fd58cfd64bcc58c03879f274b1e4d22
98 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF was flagged by a machine learning classifier and ClamAV as malicious (Js.Exploit.HTML-30). The presence of an embedded URL and XFA form suggests an attempt to exploit vulnerabilities within the PDF reader. The ClamAV detection indicates the likely presence and execution of JavaScript, which is commonly used to download and execute further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Js.Exploit.HTML-30 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Js.Exploit.HTML-30
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/