Malicious PDF — malware analysis report

Static analysis result for SHA-256 f4a74572542c93b3…

MALICIOUS

PDF

150.9 KB
MD5: f2dfb731e297d01754a9066f888fbecc SHA-1: 6ad617eea9ce1d2116d1046d9eae31653ed8f34b SHA-256: f4a74572542c93b304d13330fa36620607d5d171324f39f4b278b07a86590b98
90 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The file was flagged by a machine learning classifier and ClamAV as malicious, specifically identified as a PDF dropper. The document body contains obfuscated binary data, typical of malicious PDFs designed to drop further payloads. No specific URLs or scripts were extracted, but the overall behavior indicates a dropper functionality.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9977

Heuristics 1

  • ClamAV: Pdf.Dropper.Agent-7391774-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7391774-0