Malicious PDF — malware analysis report

Static analysis result for SHA-256 bbe165baee0de5aa…

MALICIOUS

PDF

28.0 KB
MD5: d711c42f7e775c51454c41039ea751dd SHA-1: 4314b719449c42237a4d780c31cc9ae391ee11b4 SHA-256: bbe165baee0de5aa9a2e01b107c27a66f2ea38f4f8697d27cea9acba49b98cb2
98 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF was flagged by a machine learning classifier and ClamAV as malicious, specifically identifying it as Js.Exploit.HTML-30. The presence of an XFA form suggests an attempt to leverage form processing for exploitation. An embedded URL was also found, likely used to host or retrieve malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Js.Exploit.HTML-30 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Js.Exploit.HTML-30
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/