Pdf.Dropper.Agent — PDF malware analysis

Static analysis result for SHA-256 24a393317ce426a4…

MALICIOUS

PDF

44.7 KB
MD5: 714e7db186e1d6bf757f8da353635430 SHA-1: 46168938b237df797aed7de289946b66f597396f SHA-256: 24a393317ce426a4a6a9fc6ada125b466dd654532fc4505c089a8d94a57d33ff
104 Risk Score

Malware Insights

Pdf.Dropper.Agent · confidence 95%

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The critical ClamAV detection and multiple PDF-specific heuristics, including embedded JavaScript and ASCIIHexDecode filters, indicate a malicious PDF. The embedded JavaScript is likely responsible for downloading and executing a second-stage payload, as suggested by the 'Pdf.Dropper.Agent' family name. The document body is not human-readable, further supporting a malicious intent.

Heuristics 5

  • ClamAV: Pdf.Dropper.Agent-7089091-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7089091-0
  • ASCIIHexDecode filter (with exploit indicators) medium PDF_FILTER_HEX
    Hex-encoding filter present alongside exploit delivery indicators — often used to hide payload or shellcode bytes
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0011_000.js
684b219ec31d517d0d923860e55c62481aef7973585ad66ffeb574e0e7ece257
pdf-javascript-stream PDF /JS object 11 at offset 0xA1CA 3902 bytes
font_00_sfnt_off0000044b.bin
4f69fdbf43eabdd5abc64b7ad9a9f03684a5a3891541c393a6d57875ac98036c
pdf-font-stream PDF embedded font (sfnt) at offset 0x44B 65932 bytes