Malicious PDF — malware analysis report

Static analysis result for SHA-256 a09782830aa01158…

MALICIOUS

PDF

28.3 KB
MD5: ca368643f1a829e6badc82c77640dc9b SHA-1: 57767005aa507f9ab3bc3beb524cba66bbb701c6 SHA-256: a09782830aa01158a8ac14f2dbe84a66d5d2f15d9e4c750187e509bf5ff34323
98 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing Attachment

The file is a PDF identified as malicious by ClamAV (Js.Exploit.HTML-30) and a machine learning classifier. It contains an embedded URL and utilizes XFA forms, which are often exploited to deliver malicious content. The presence of JavaScript exploitation indicators suggests it attempts to download and execute a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Js.Exploit.HTML-30 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Js.Exploit.HTML-30
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/