Malicious PDF — malware analysis report

Static analysis result for SHA-256 ce9b02f6046127fb…

MALICIOUS

PDF

31.9 KB
MD5: ccac466c385a5ecf2a3b52004fb761be SHA-1: aad91e045f34a217a10843974f5892b1a166e485 SHA-256: ce9b02f6046127fbd867e656ea17b381be262fdf8a2df8fef25de7a8ef23a87a
98 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF was flagged by a machine learning classifier and ClamAV as malicious, specifically identifying it as Js.Exploit.HTML-30. The presence of an XFA form and an embedded URL suggests an attempt to exploit vulnerabilities or trick the user into executing malicious content. The embedded JavaScript, though partially obfuscated, likely facilitates the download and execution of a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Js.Exploit.HTML-30 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Js.Exploit.HTML-30
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/