Pdf.Dropper.Agent-7251648-0 — PDF malware analysis

Static analysis result for SHA-256 3c19798d1eef667f…

MALICIOUS

PDF

33.0 KB
MD5: 79a5728d30de3aea89196ec65714f914 SHA-1: 84da1245901600e2c51b1e20519a2dcdb2279491 SHA-256: 3c19798d1eef667fce65752b853cad96134ca2214db118343ed1be37797125ec
76 Risk Score

Malware Insights

Pdf.Dropper.Agent-7251648-0 · confidence 85%

MITRE ATT&CK
T1204.002 Malicious File: User Execution: Malicious File

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. ClamAV detection identifies this as 'Pdf.Dropper.Agent-7251648-0', suggesting its purpose is to drop or download additional malicious content. No specific URLs or further script details were extracted for inclusion as IOCs.

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7251648-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7251648-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.