Pdf.Dropper.Agent-7285171-0 — PDF malware analysis

Static analysis result for SHA-256 988ac1b1bd72f275…

MALICIOUS

PDF

54.3 KB
MD5: 347c8029c8937ac1be61eb771b3a844c SHA-1: 5f518ec6f85cabc69e16a85b21a50eaebb0a5fae SHA-256: 988ac1b1bd72f275a3d7621b02c15f25e93855ee896690d41396746e6f001af2
106 Risk Score

Malware Insights

Pdf.Dropper.Agent-7285171-0 · confidence 99%

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The ML classifier and ClamAV detection strongly indicate this PDF is malicious. The presence of embedded JavaScript actions and streams suggests it is a dropper, likely intended to download and execute a secondary payload. The specific ClamAV signature points to a known dropper agent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7285171-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7285171-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.