Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca2c7d5385119eb9…

MALICIOUS

PDF

29.2 KB
MD5: c3e0946edd1021c2a5e103ec1bce51e8 SHA-1: f8e6496eae13c49ab4bf31ef44c6f6116fecd736 SHA-256: ca2c7d5385119eb9a64f557df77f212e5dfa2307d890982c94d27070febbf69a
100 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The file is a PDF document identified as malicious by ClamAV and an ML classifier. It contains an embedded URL and utilizes XFA forms, indicating a potential exploit. The presence of JavaScript, as flagged by ClamAV's 'Js.Exploit.HTML-30' detection, suggests the document is designed to download and execute a malicious payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Js.Exploit.HTML-30 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Js.Exploit.HTML-30
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PSEOF. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/