PDF static analysis report

Static analysis result for SHA-256 2ad47e12d2339716…

CLEAN

PDF

1.52 MB First seen: 2026-05-19
MD5: f4f1a52a5dc8c677620d8562ca77d955 SHA-1: d0b06221d7ae2467d5fb02b1e484d743610c2af8 SHA-256: 2ad47e12d2339716effd2b4beacba4ab5ddc909fa08c8f005c898347143a12d5
22 Risk Score

🔏 Digital signature Self-signed

A signature covers the whole signed byte range — PDF JavaScript is never signed on its own — and does not by itself mean the document is safe.

Machine Learning

  • Nyx PDF Classifier clean score 0.0002

Heuristics 5

  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.leppard.co.za/ PDF link annotation
    • https://wwww.microsoft.com0In extracted file (stream_014_off0000d2a8.bin)
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • https://docs.microsoft.com/typography/abouthttp://lucasfonts.comMicrosoftIn extracted file (stream_014_off0000d2a8.bin)
    • http://en.wikipedia.org/wiki/MIT_LicenseIn extracted file (stream_014_off0000d2a8.bin)
    • http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl0ZIn extracted file (stream_014_off0000d2a8.bin)
    • http://www.microsoft.com/pki/certs/MicCodSigPCA_2010-07-06.crt0In extracted file (stream_014_off0000d2a8.bin)
    • http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0ZIn extracted file (stream_014_off0000d2a8.bin)
    • http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0��In extracted file (stream_014_off0000d2a8.bin)
    • http://www.microsoft.com/PKI/docs/CPS/default.htm0@In extracted file (stream_014_off0000d2a8.bin)
    • http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl0ZIn extracted file (stream_014_off0000d2a8.bin)
    • http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0In extracted file (stream_014_off0000d2a8.bin)
    • http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0lIn extracted file (stream_015_off0001e0bd.bin)
    • http://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0In extracted file (stream_015_off0001e0bd.bin)
    • http://www.microsoft.com/pkiops/Docs/Repository.htm0In extracted file (stream_015_off0001e0bd.bin)
    • http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0In extracted file (stream_015_off0001e0bd.bin)

Extracted artifacts 8

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_014_off0000d2a8.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xD2A8 168096 bytes
SHA-256: fd0d87dfe6739dc922e8ba1333289d43584e35c2431497e303cf04ac455a0d2d
stream_015_off0001e0bd.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1E0BD 126212 bytes
SHA-256: c5715fc72990453a89e8dbd1f42aa30348acc74778de573dd08c1df9bc4b9ff8
font_00_sfnt_off000084e6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x84E6 63556 bytes
SHA-256: 6f80d95afac6336bfc9523625160dcd3287181bc4c05dab7d68f913ca9929ecc
font_03_sfnt_off0002ca8f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2CA8F 76740 bytes
SHA-256: 0b50dad0777e5948f806fdc611bdef2056fc261bb209f856d9e0267eb45e6cb2
font_04_sfnt_off0004b91c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4B91C 60316 bytes
SHA-256: b54f2b6859e7850df362b2e78d73875c01584822e1ea3ad5a93abb5633520cd3
font_05_sfnt_off00057b0d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x57B0D 60728 bytes
SHA-256: c0e602628dbc6867166c3b500d4627a66c6a04e4f37a60ccf660b4806a1538a4
font_06_sfnt_off00147660.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x147660 61348 bytes
SHA-256: 4fc5f195aa8f1a0a44343bac4006a911c6888c7fc820f7ca69d46b225be9d1a4
font_07_cff_off0017147e.bin pdf-font-stream PDF embedded font (cff) at offset 0x17147E 86093 bytes
SHA-256: 427af119e8f704848644710f5da65ea8d385162ce3d78bb774a2b0bda4893f95
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.45, consistent with packed or encrypted content.