Pdf.Dropper.Agent-7417864-0 — PDF malware analysis

Static analysis result for SHA-256 351ec4bab163ac6b…

MALICIOUS

PDF

11.7 KB Created: 2010-07-25 10:32:51
MD5: 1afc04aabc1d80e6f10def67e550c4d0 SHA-1: e79e7a90270e849bfe2fa294f7c3cfed9103be8f SHA-256: 351ec4bab163ac6b53f0e7cdcc10a0dffcff57c5d6cfe4a7eb97f13c43aa086b
116 Risk Score

Malware Insights

Pdf.Dropper.Agent-7417864-0 · confidence 99%

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF was flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Dropper.Agent-7417864-0' and a high ML score. Embedded JavaScript was detected, indicating the likely execution of malicious code. The ML classifier's output of 0.999988 strongly supports the malicious verdict. The document body contained unreadable characters, suggesting it is not intended for human consumption.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7417864-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7417864-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
a7e18fd1563aa33b012672b749943f76345cae17fc065c5c1aae0d786099e329
pdf-javascript-stream PDF /JS object 7 at offset 0x2AF7 588 bytes