Malicious PDF — malware analysis report

Static analysis result for SHA-256 0f19f93ccc0aade6…

MALICIOUS

PDF

29.0 KB
MD5: ef84072c3e5e94b46d86904bab75930c SHA-1: 8b193958b03f0e2fe207c08f77d6ab3869c6d522 SHA-256: 0f19f93ccc0aade61081dff33a5dc41349e9aec9c0ec8cc42e9df3c8eff806c6
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment

The PDF file was flagged by multiple heuristics, including a critical ClamAV detection for Pdf.Dropper.Agent-7229213-0 and a high ML score. Embedded JavaScript actions were identified, indicating the likely intent to download and execute a second-stage payload. The presence of JavaScript points to T1059.007, and the overall nature suggests it was likely delivered as a spearphishing attachment (T1566.001).

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7229213-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7229213-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.