Malicious PDF — malware analysis report

Static analysis result for SHA-256 45878ea619c4a768…

MALICIOUS

PDF

8.1 KB
MD5: 1a9c72415c8c5dd553ea52ac2a4de5b2 SHA-1: d50025ba2d810ae09ca340cd4cd03cb89c599561 SHA-256: 45878ea619c4a7687e5c5a6f7f68585f36234d273c30bba69250e81b02f65ef2
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF contains embedded JavaScript, indicated by PDF_JAVASCRIPT and PDF_JS heuristics. ML classification and ClamAV detection strongly suggest malicious intent, specifically identifying it as Pdf.Exploit.Agent-21119. The presence of JavaScript points to an exploit attempt, likely to download and execute a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-21119 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-21119
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.