Pdf.Dropper.Agent-7295287-0 — PDF malware analysis

Static analysis result for SHA-256 b5598218e2d77bab…

MALICIOUS

PDF

34.5 KB
MD5: 5b7d26634762be8fc59bb94921fb41db SHA-1: b96d859b4db133907da9605c505ae622a5b358c6 SHA-256: b5598218e2d77bab5ab861580c0226225d4026ec8ca269ca8a43551602882c3b
76 Risk Score

Malware Insights

Pdf.Dropper.Agent-7295287-0 · confidence 95%

The critical ClamAV heuristic identifies this PDF as Pdf.Dropper.Agent-7295287-0, indicating it functions as a dropper. Low-severity heuristics for JavaScript actions and embedded JS streams further support the presence of malicious scripting. These scripts are likely responsible for downloading and executing a second-stage payload.

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7295287-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7295287-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.