Pdf.Dropper.Agent-9448479-0 — PDF malware analysis

Static analysis result for SHA-256 6aafe6222aadb0ad…

MALICIOUS

PDF

8.0 KB
MD5: b81d23e5da031f75ebb41452e317d885 SHA-1: aadeaaa05f5e75b2c279ac1e7b5663a67992270c SHA-256: 6aafe6222aadb0ad0b608081f726b14f82d711f8328561bf4e893d5251f5f517
106 Risk Score

Malware Insights

Pdf.Dropper.Agent-9448479-0 · confidence 95%

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV and a machine learning classifier, indicating a high likelihood of malicious intent. Embedded JavaScript actions and streams strongly suggest the document is designed to execute code, likely to download a secondary payload. The presence of JavaScript points to the T1059.007 technique, and the nature of the file as a potential attachment suggests T1566.001.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-9448479-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-9448479-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.