Pdf.Dropper.Agent — PDF malware analysis

Static analysis result for SHA-256 51bb3380f7cee2c4…

MALICIOUS

PDF

4.9 KB
MD5: 95f25a574ebc3f704156ba3dd10d75f8 SHA-1: ac2e553bc3f4eb59a1c3d4cbf5905018890d514c SHA-256: 51bb3380f7cee2c4309befbc09ac7d69463d19484019ba0f4bc293f1d1e5665c
76 Risk Score

Malware Insights

Pdf.Dropper.Agent · confidence 95%

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF contains embedded JavaScript, indicated by heuristic firings for PDF_JAVASCRIPT and PDF_JS. ClamAV detection identifies the file as Pdf.Dropper.Agent-7212701-0, a known dropper. This suggests the PDF's primary function is to download and execute a secondary malicious payload.

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7212701-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7212701-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.