PDF static analysis report

Static analysis result for SHA-256 2cdafb0983f4e363…

CLEAN

PDF

14.85 MB First seen: 2020-09-24
MD5: 0b72d89439d655a6581885917a11a3ba SHA-1: 950ee0e841f1b617deffe1a0badecd6d971fbda2 SHA-256: 2cdafb0983f4e363b853988c0c07fddc191d7c205a8294c6d52bc6fc7c1b9377
22 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0572

Heuristics 2

  • Unusually high stream count medium PDF_MANY_STREAMS
    PDF contains 501+ stream objects — may indicate heap spray or heavy obfuscation
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://www.npes.org/pdfx/ns/id/In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text
    • http://ns.adobe.com/pdfx/1.3/In PDF document text
    • http://www.iec.chIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
icc_00_off00001592.icc pdf-icc-profile PDF ICC profile at offset 0x1592 3144 bytes
SHA-256: 2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
font_00_sfnt_off00e7af08.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE7AF08 52460 bytes
SHA-256: ec48467746ea32e99b5589e3d6c0b5412856de92e2841cd0e432697ac2bd55c1
font_01_cff_off00e8c0d5.bin pdf-font-stream PDF embedded font (cff) at offset 0xE8C0D5 270 bytes
SHA-256: 0cb83a68aab073d530fd23ddd2c5f396efc99710e3e1d29a989ddc7efabbe84b