Malicious PDF — malware analysis report

Static analysis result for SHA-256 e44432d845a4cd2e…

MALICIOUS

PDF

31.7 KB
MD5: 92c3285ebba423dd77353fb73f30d52b SHA-1: 24387ce986603b60ab6b5cca8267e636c787b940 SHA-256: e44432d845a4cd2e81de9c72aa9e72e963c7b00b48cb0d5967f20c7ec88addb2
68 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file is a PDF containing an XFA form, which is a known vector for embedding malicious content. Heuristics indicate the presence of JavaScript exploits. The embedded URL is likely part of the exploit chain. The document body contains obfuscated JavaScript code that appears to be attempting to execute malicious actions, likely related to the Js.Exploit.HTML-30 detection.

Heuristics 3

  • ClamAV: Js.Exploit.HTML-30 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Js.Exploit.HTML-30
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/