Pdf.Dropper.Agent-6331533-0 — PDF malware analysis

Static analysis result for SHA-256 1582c9280eea074e…

MALICIOUS

PDF

809.3 KB First seen: 2026-05-03
MD5: 3119abba449d16355ceb385fd778b525 SHA-1: e7cba013867d508b5322c483db20fa54bf5cc0f7 SHA-256: 1582c9280eea074ec938f0f923fbd4405cd40677e869afffa87b44b71855a941
120 Risk Score

🔏 Digital signature Signature invalid

A signature covers the whole signed byte range — PDF JavaScript is never signed on its own — and does not by itself mean the document is safe.

Malware Insights

Pdf.Dropper.Agent-6331533-0 · confidence 95%

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The sample is a PDF file flagged as malicious by ClamAV (Pdf.Dropper.Agent-6331533-0) and an ML classifier. It contains embedded JavaScript, which is a common method for exploiting PDF vulnerabilities and delivering secondary payloads. The invalid digital signature further suggests malicious intent, as it may be an attempt to deceive users about the document's authenticity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Dropper.Agent-6331533-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-6331533-0
  • PDF digital signature is cryptographically invalid medium PDF_SIGNATURE_INVALID
    A signature's CMS failed verification: either the signer's signature over the signed attributes is invalid, or the signed content digest does not match the bytes the ByteRange covers. The signature was tampered with, forged, or the signed content was altered.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/ In extracted file (stream_000_off0006d90c.js)
    • http://www.xfa.org/schema/xci/3.0/In extracted file (stream_000_off0006d90c.js)
    • http://www.xfa.org/schema/xfa-template/2.8/In extracted file (stream_000_off0006d90c.js)
    • http://www.xfa.org/schema/xfa-data/1.0/In extracted file (stream_000_off0006d90c.js)

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_000_off0006d90c.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6D90C 289498 bytes
SHA-256: dcefc16710d335e69f60cdd8a0e174d43939d02eaa8dd4c6d7ce4ca63f06495b