PDF / .VIR static analysis report

Static analysis result for SHA-256 3756a649d5539897…

ERROR

PDF / .VIR

1.50 MB Created: 2019-08-22 11:33:27 +06:00 Authoring application: Microsoft® Word 2016 First seen: 2024-10-29
MD5: 9128259a7768d4b9deb35b8349049879 SHA-1: 72255f176e3a774aabd5471871464bc3ec5f74ef SHA-256: 3756a649d5539897e8031dd5dca507fe21fa11233587a964f65aff35e555e651
14 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0002

Heuristics 4

  • TrueType bitmap font + active content — CVE-2023-26369 related info CVE related PDF_CVE_2023_26369_RELATED
    PDF embeds a TrueType font with bitmap tables (EBDT/sbix/CBDT) alongside exploit delivery indicators — CVE-2023-26369 exploits the sfac_GetSbitBitmap function in Adobe's libCoolType for arbitrary code execution. This CVE was actively exploited in the wild, but this rule does not validate the malformed EBLC/EBDT primitive.
  • PDF static-analysis soft budget exhausted low SCAN_INCOMPLETE
    The bounded PDF scanner skipped late sub-format walkers after the configured per-file soft deadline. Earlier findings remain valid.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.hydromet.gov.bt/ PDF link annotation
    • http://www.nchm.gov.bt/In PDF document text
    • https://www.facebook.com/NationalCenterforHydrologyandMeteorology/In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text