Malicious PDF — malware analysis report

Static analysis result for SHA-256 e38315afcd421d8a…

MALICIOUS

PDF

31.7 KB
MD5: 5481cd63950142a6f41337a338dbd226 SHA-1: 4e0cf863bb6d5f5c931952a69e210aba24c3a8a4 SHA-256: e38315afcd421d8a2e5968a244983b5b55b83f16a75b38a16a5a5cc26d838718
70 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The sample is a PDF file identified as malicious by ClamAV with the signature Js.Exploit.HTML-30. It contains an XFA form, which is often used to embed executable content. The embedded JavaScript, although obfuscated, appears to be designed to exploit vulnerabilities within the PDF viewer. The reconstructed JavaScript string 'app.alert(1);for(i=0;i-74860<0;i+=2){z=i;test();ry{new Number().prototype.a1;}}catch(qwa){eval(s qwe123ba[0] /CourierStd 10 Tf 0 g qwe123ba asdvsa[0] a1[0] /Helv 0 Tf 0 g' suggests an attempt to execute arbitrary code. The presence of an embedded URL further supports the likelihood of a download or redirection to a malicious payload.

Heuristics 4

  • ClamAV: Js.Exploit.HTML-30 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Js.Exploit.HTML-30
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PSEOF. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.x&#102;a.org/schema/xfa-template/2.5/