Malicious PDF — malware analysis report

Static analysis result for SHA-256 bc1c7463353c60b6…

MALICIOUS

PDF

226.8 KB
MD5: 18a42c3cdc2f251545ad026a3c739b65 SHA-1: 13bb71ba1a00389e51f8264b2f478bdb14ef65d3 SHA-256: bc1c7463353c60b66d8b02dd582abef431b8dcaa8b9d4d674942001cde878b8e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The file is identified as malicious by both a machine learning classifier and ClamAV, which specifically labels it as Pdf.Dropper.Agent-7217084-0. The document body contains generic text suggesting it's a lure. The primary function appears to be dropping a malicious payload, consistent with a dropper malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9956

Heuristics 1

  • ClamAV: Pdf.Dropper.Agent-7217084-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7217084-0