Malicious PDF — malware analysis report

Static analysis result for SHA-256 c0ed5f18634155ca…

MALICIOUS

PDF

287 B
MD5: 59ffaa8c04ed36ff2b02a29d15c81afe SHA-1: 4ce136c2a35cddc70dc8b2eee7220fa1b6b08dd0 SHA-256: c0ed5f18634155caeb2e7c074252e7406e8cadda0b4698bf5004b3224cc5d0a1
70 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1204.002 Malicious Link: Malicious File

The PDF file contains a launch action, indicating it is designed to automatically execute a payload when opened. The ML classifier strongly suggests malicious intent. While no specific family is identified, the technique points to a downloader or dropper.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 1

  • Launch action high PDF_LAUNCH
    PDF contains a /Launch action with an unresolved or extension-less target — treat as potentially dangerous