Malicious PDF — malware analysis report

Static analysis result for SHA-256 ff1bc8a0f36e64ca…

MALICIOUS

PDF

28.3 KB
MD5: a4320180e8a7a33bb7ba7c386f43fcfa SHA-1: 16861c91666087d46758fe39ea236f6cb9291677 SHA-256: ff1bc8a0f36e64ca9665df011fdb0065f5e767444ca5a4de5b95e7b90cceaeb0
100 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The file is a PDF containing an XFA form, which is often used to embed malicious content. ClamAV detected it as Js.Exploit.HTML-30, indicating the presence of exploit code, likely JavaScript. The ML classifier also strongly flagged it as malicious. The embedded URL, while seemingly benign, is part of the XFA structure and may be used in conjunction with the exploit.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Js.Exploit.HTML-30 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Js.Exploit.HTML-30
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PSEOF. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/