Malicious PDF — malware analysis report

Static analysis result for SHA-256 421a7f66eed4ded9…

MALICIOUS

PDF

17.7 KB
MD5: 90031f1725d183dd5ea8e5f345ff4b04 SHA-1: 81b04251ac1094bd7a89785031c2b828419ecb6e SHA-256: 421a7f66eed4ded93970e644dcc187498de0931516dc8ab5232f5207b76a006c
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The primary indicator of maliciousness is the ClamAV detection of 'Pdf.Dropper.Agent-7166077-0'. This suggests the PDF is designed to deliver and execute other malicious content. No specific family could be identified from the available evidence.

Heuristics 1

  • ClamAV: Pdf.Dropper.Agent-7166077-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7166077-0

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_000_off000003eb.bin
44fa9f805f28d2cc610980554af38ceefaf1a9d8ecbf2f8179d1ae634d47f3e1
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3EB 428297 bytes