Malicious PDF — malware analysis report

Static analysis result for SHA-256 31d6e2c5ce7bb2ff…

MALICIOUS

PDF

150.9 KB
MD5: 3f3311df57f0baf1c68afa79e9420a8b SHA-1: d4b6540cb21b44f9ba090660731e8e300c543751 SHA-256: 31d6e2c5ce7bb2ff0a46c1482e13a9c6e4f525b174b70a5e26d78051c0276dff
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The file is identified as a PDF dropper by ClamAV, indicating it is designed to deliver other malware. The presence of obfuscated binary data within the document body suggests an attempt to hide malicious content, likely an exploit or a downloader. The primary function appears to be the initial compromise and subsequent payload delivery.

Heuristics 1

  • ClamAV: Pdf.Dropper.Agent-7246391-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7246391-0