Malicious PDF — malware analysis report

Static analysis result for SHA-256 e3f3da2bcefd8c60…

MALICIOUS

PDF

150.9 KB
MD5: 5e1a5ff6ce951c7d2c20f29b60108a96 SHA-1: d1d2236e327758e9dac190bf03a78d59417288f6 SHA-256: e3f3da2bcefd8c60030b971dc28210440b4a2ac9c962715dfa741b347e4dd132
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The file is identified as a malicious PDF by ClamAV, specifically a dropper. The document body contains seemingly random data, suggesting it is not intended for direct user interaction but rather to exploit a vulnerability or trigger embedded malicious content. The primary function appears to be delivering a secondary payload.

Heuristics 1

  • ClamAV: Pdf.Dropper.Agent-7316048-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7316048-0