Malicious PDF — malware analysis report

Static analysis result for SHA-256 6e0994ca3ca47f18…

MALICIOUS

PDF

124.4 KB Created: ~qϊsDèp˜¡6C¤kó{%‡nQš Authoring application: Ä´ýþ¾6u¸@× (via Ä´ýõ¾4u¼@ΐ@wöY£VÖÃ^½(-¡ßpGysY)
MD5: cc71707e46f3e6306269f30461c518cd SHA-1: 08d759cf67af01eb1541c752f34135f7cb09aa85 SHA-256: 6e0994ca3ca47f18729c9578d457f34650a0bd97821863afcca38e1625d07fb5
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ClamAV with the signature Pdf.Dropper.Agent-7270533-0. It is an encrypted PDF with an OpenAction, indicating that the payload is hidden from static analysis. The PDF is also flagged as an image-only lure, suggesting it contains a screenshot designed to trick users into interacting with a hidden malicious element.

Machine Learning

  • Nyx PDF Classifier clean score 0.1319

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7270533-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7270533-0
  • Encrypted PDF carries /OpenAction — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/OpenAction). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 2 image(s), only 0 text block(s), carries a click-outward action, and is only 124 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.