CLEAN
20
Risk Score
Machine Learning
- Nyx PDF Classifier clean score 0.0055
Heuristics 4
-
JavaScript action low 1 related finding PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://www.adobe.com/products/acrobat/readstep2.htmlReferenced by PDF JavaScript
Extracted artifacts 12
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_002_off0000065e.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x65E | 316 bytes |
SHA-256: 1906cab1202c79e7bef6104f4f256de33eea823c62d41539b2cc51a0a4ebaa8d |
|||
stream_069_off00005155.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x5155 | 20986 bytes |
SHA-256: 603b5c613625248e94390a7c9c39129e20a1591d5516ba42e03eb97ee9a523a8 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 5 long base64-like blob(s).
|
|||
stream_090_off000180cb.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x180CB | 3319 bytes |
SHA-256: 5039a3aade803a9282bf093a49a9c3fa6958b70df10612c2fe98e9898ec70e4b |
|||
stream_128_off00029f3d.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x29F3D | 8203 bytes |
SHA-256: 6eb688cc418e554e676c2bfd1ee1012c927335f0acb7331b496eaf1c6d9542c7 |
|||
objstm_0211_00.bin |
pdf-objstm-decoded | PDF /ObjStm 211 0 obj (inflated) | 979 bytes |
SHA-256: 7dc7b0e2709ef23a7075d1328a96f3476e3498e8e98529a8b77a166e78f10f83 |
|||
objstm_0038_00.bin |
pdf-objstm-decoded | PDF /ObjStm 38 0 obj (inflated) | 2495 bytes |
SHA-256: fee331a9f2ac96cf0852efd3d4529cd68375aa134ef667b92b2b1c7498b8bf47 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 long base64-like blob(s).
|
|||
font_00_cff_off0000a79d.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0xA79D | 5070 bytes |
SHA-256: bad0b0d6572d400f868f0b7d4ee491a64f69c86c37546eba248c38a95679e3d6 |
|||
font_01_cff_off0000b85d.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0xB85D | 4647 bytes |
SHA-256: 51e80b91622307c09e2211482b9d5427b29a60b7e6b0b1ea5ff69b7280013d33 |
|||
font_02_cff_off00017234.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x17234 | 3687 bytes |
SHA-256: 414ef9af601366feb47f88d69999df8c594f08946db25e79349469813f0d2cef |
|||
font_03_cff_off00017b5a.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x17B5A | 277 bytes |
SHA-256: be883c017af8a0e9708156b53c3c67b2ef563ab31d9100886bebb54e4a16e88d |
|||
font_04_cff_off0001848f.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x1848F | 2410 bytes |
SHA-256: df81db286d71d40737a303989f75cccfd730219b33f8e3be0089a2f12c6f02df |
|||
font_05_cff_off00018da7.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x18DA7 | 272 bytes |
SHA-256: b8f59acebd1d660c2f312af569781c4d49386c65cb4887c7686e08cfadd6831f |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.