PDF / .VIR static analysis report

Static analysis result for SHA-256 0f53dab50cf237b7…

CLEAN

PDF / .VIR

6.71 MB First seen: 2026-05-28
MD5: f3367251a4293cee33852289bd58531d SHA-1: e686ed1682bdffc547a53d2ea5eee60fbc0b717c SHA-256: 0f53dab50cf237b7ba256ac13b415d32206c6294e1d2bcb9486cac4b4d2b76a1
4 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0272

Heuristics 2

  • JPXDecode + active content — JPEG2000 CVE-family indicator info CVE related PDF_JPX_CVE_2018_4990_RELATED
    PDF uses /JPXDecode (JPEG2000) alongside JavaScript, XFA, or RichMedia indicators. This matches the delivery pattern for Adobe Reader JPEG2000 parser exploit families, including CVE-2018-4990, but does not prove the exact malformed JP2/JPX primitive.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_011_off000039fb.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x39FB 557168 bytes
SHA-256: 35f401731df11a4eba3502af632e51d68bc394bcb7d34632a331c1ba3f4a0bf6
stream_092_off003b8d9d.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3B8D9D 390141 bytes
SHA-256: deec6436ae1ed477de051d90a2bff3d47d2c227d10413a6ffeba651a4c6b9b4c