Malicious PDF — malware analysis report

Static analysis result for SHA-256 32021a5609fcbcef…

MALICIOUS

PDF

43.6 KB
MD5: 33b94a13b7aa96a59d414d606f804563 SHA-1: 7d632833a53f1561c92018dd809a5ab92baac6f0 SHA-256: 32021a5609fcbcef183c37d3d2d7211deb60f91669e52b0c354da49d0cfdd672
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF contains embedded JavaScript, flagged by multiple heuristics as malicious. The ML classifier and ClamAV detection strongly indicate malicious intent, likely to download and execute a secondary payload. The specific attack pattern is inferred from the dropper classification.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7246456-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7246456-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.