Malicious PDF — malware analysis report

Static analysis result for SHA-256 f9857670f26e5443…

MALICIOUS

PDF

150.9 KB
MD5: 22c2f726696b9820939791c0d86818a4 SHA-1: 4463f9b0040f49314d23148072d4de30050a3f63 SHA-256: f9857670f26e5443a62c235c994a02787d2a4c348766fdec102906ec8dc1e51f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file is identified as malicious by both a machine learning classifier and ClamAV, which specifically labels it as 'Pdf.Dropper.Agent-7326428-0'. The document body contains generic text suggesting it is a lure. The primary function appears to be dropping a malicious payload, consistent with a dropper malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9977

Heuristics 1

  • ClamAV: Pdf.Dropper.Agent-7326428-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7326428-0