Malicious PDF — malware analysis report

Static analysis result for SHA-256 a2e53a76860cb7bd…

MALICIOUS

PDF

31.9 KB
MD5: 9898134638e70bd93e4a8d15fd7967a6 SHA-1: 819afcca5491e70bcbae679a4dcd3b163c38ff7e SHA-256: a2e53a76860cb7bdd35d68f68cbc6922124251a87821eeda98ca28016019ce96
98 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF was flagged by a machine learning classifier and ClamAV as a JavaScript exploit. The presence of an XFA form suggests an attempt to leverage form functionality for malicious purposes. The embedded URL, while seemingly benign, is part of the exploit chain. The script likely attempts to download and execute a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Js.Exploit.HTML-30 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Js.Exploit.HTML-30
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/