Malicious PDF — malware analysis report

Static analysis result for SHA-256 2abae3c68698cfcb…

MALICIOUS

PDF

2.0 KB
MD5: f909eba16029e246310718ecc1142334 SHA-1: 9fde41966496b687f7f485b506e2172aea92bd3a SHA-256: 2abae3c68698cfcbfdceed768a56abf46f5518ed0c7877aea288e63606fff1bf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file was flagged by a machine learning classifier with high confidence and also detected by ClamAV as Win.Exploit.Unicode_Mixed-1. This indicates the file is likely a malicious PDF designed to exploit a vulnerability, commonly delivered via spearphishing attachments.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9622

Heuristics 1

  • ClamAV: Win.Exploit.Unicode_Mixed-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Exploit.Unicode_Mixed-1