Malicious PDF — malware analysis report

Static analysis result for SHA-256 1c8d5cd1589f959b…

MALICIOUS

PDF

127.5 KB Authoring application: PyPDF2 First seen: 2026-06-11
MD5: 5da7ec927d5df0f56df7ad8f6a54aa9e SHA-1: ea424e2c9741dde4eb19652f0b10c8dd03ad7f9e SHA-256: 1c8d5cd1589f959b376f29ab5ef1dc40ff611ce273a6201e4f63acdc4be72dfe
62 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0006

Heuristics 3

  • Image-heavy PDF hides clickable URL with PDF string escapes high PDF_ESCAPED_URI_IMAGE_LURE
    PDF is image-heavy with little real text and its clickable HTTP(S) URI is encoded with PDF octal escapes. This combination is common in credential-phishing PDFs that render a screenshot-like prompt and obscure the destination from simple URL extractors.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 1 text block(s), carries a click-outward action, and is only 127 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://spoo.me/22XAPsR In PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000183a9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x183A9 51872 bytes
SHA-256: 78e69a8fc8a7e329fa70ba6b8f0c905158c099d8a68bb6176677c77c5ca4eed4
font_01_sfnt_off0001d152.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1D152 5720 bytes
SHA-256: 3fcce20831385ddca193d453063498ace1b3916dd11d9037c3a695716b9b64a8
font_02_sfnt_off0001e782.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1E782 5236 bytes
SHA-256: db0faffbe7b45fb4c5a0c9e04b78a28e4f3dc1b82f95d14f605b03ee5dbab51e