CLEAN
22
Risk Score
Machine Learning
- Nyx PDF Classifier clean score 0.0001
Heuristics 2
-
Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://wwww.microsoft.com0 In PDF document text
- http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text
- http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl0ZIn PDF document text
- http://www.microsoft.com/pki/certs/MicCodSigPCA_2010-07-06.crt0In PDF document text
- http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0ZIn PDF document text
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0��In PDF document text
- http://www.microsoft.com/PKI/docs/CPS/default.htm0@In PDF document text
- http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0lIn PDF document text
- http://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0In PDF document text
- http://www.microsoft.com/pkiops/Docs/Repository.htm0In PDF document text
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0In PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_001_off0001c01a.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1C01A | 370564 bytes |
SHA-256: d19b71779f9a27b28b0a5d8cef02b2380c5f57a5bcd49e834b193590bb58a582 |
|||
font_00_sfnt_off00032722.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x32722 | 256044 bytes |
SHA-256: 489ef126e018e8e197d11b6fcc190396c46661ccbfd353fa6610936447d8f933 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Static shellcode analysis found candidate code region(s). Indicators: heap spray 0x04
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.