MALICIOUS
106
Risk Score
Malware Insights
MITRE ATT&CK
T1204 Malicious Link
This PDF file was flagged as malicious by multiple engines, including a high-confidence ML classifier and ClamAV, which identified it as Pdf.Exploit.Agent-20335. Static analysis revealed embedded JavaScript actions and streams, indicating an attempt to execute malicious code upon opening. The presence of these elements strongly suggests the PDF is intended to exploit vulnerabilities and download a secondary payload.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
ClamAV: Pdf.Exploit.Agent-20335 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Exploit.Agent-20335
-
JavaScript action low PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
Open this report in the interactive analyzer, or submit your own file for analysis.