SUSPICIOUS
26
Risk Score
Machine Learning
- Nyx PDF Classifier clean score 0.0001
Heuristics 4
-
TrueType bitmap font + active content — CVE-2023-26369 related info PDF_CVE_2023_26369_RELATEDPDF embeds a TrueType font with bitmap tables (EBDT/sbix/CBDT) alongside exploit delivery indicators — CVE-2023-26369 exploits the sfac_GetSbitBitmap function in Adobe's libCoolType for arbitrary code execution. This CVE was actively exploited in the wild, but this rule does not validate the malformed EBLC/EBDT primitive.
-
Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://en.wikipedia.org/wiki/Kd-tree PDF link annotation
- http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0XIn PDF document text
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0In PDF document text
- http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0aIn PDF document text
- http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0In PDF document text
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0TIn PDF document text
- http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0In PDF document text
- http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^In PDF document text
- http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0��In PDF document text
- http://www.microsoft.com/pkiops/docs/primarycps.htm0@In PDF document text
- http://www.microsoft.com/TypographyIn PDF document text
Extracted artifacts 16
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_007_off00012166.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x12166 | 1545264 bytes |
SHA-256: b51f569c8acccb9f7f2ea2e52067f37e97012c26541274df849cf89189afdcf8 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Static shellcode analysis found candidate code region(s). Indicators: heap spray 0x04
|
|||
stream_008_off00028f3b.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x28F3B | 515088 bytes |
SHA-256: bd478e81931475c2554875c8c00d3c4c51e5e4768fe689042b67b2bcb148644b |
|||
stream_017_off0004dc7c.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x4DC7C | 145632 bytes |
SHA-256: 476e900aaab652cd4cf00a16e38b2ca0a87243e5f170936a3cda54ec90775b0e |
|||
stream_024_off000535bc.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x535BC | 364818 bytes |
SHA-256: dfa3b32ab84f54b509fbdea42315fea7fe9a038243dbb480860f441b20d1e4f8 |
|||
stream_037_off000ae7e0.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0xAE7E0 | 337512 bytes |
SHA-256: 673db5463626e59fb5ba192624b5d48f299f31ebc2e5fa22fc83eeb476373a55 |
|||
stream_047_off000bd327.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0xBD327 | 337512 bytes |
SHA-256: ae16a42009a0d48d4f33bcb59a2c41ebf6563d9e48605d77e87d2f458839c8fe |
|||
stream_059_off000d36cc.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0xD36CC | 145632 bytes |
SHA-256: c161c52decf1d68496122a7b1e3063426664264561daaf112cdd54f1962b7a68 |
|||
stream_063_off000d7833.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0xD7833 | 145632 bytes |
SHA-256: b5af173645a50696e9d1b6cced6ff4daac5e7a8b8034d3e97b7770df267a04c6 |
|||
stream_088_off000f5111.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0xF5111 | 255102 bytes |
SHA-256: 404f8607641dfe23fdca64f100818912fe8d8ed256af86b2aa21c3a639b612fe |
|||
stream_105_off00101395.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x101395 | 309960 bytes |
SHA-256: df1ab4ca5a66b0e0314c2be587f902d375abfc3183997c84e9e0cee4d33513b6 |
|||
stream_117_off0010dc4f.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x10DC4F | 200490 bytes |
SHA-256: 33073847ed43a870c55d0e2a35949808479fbe4e17271e3fe4e5bd6f97befa0d |
|||
stream_133_off001165f4.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1165F4 | 227796 bytes |
SHA-256: 2f36f0e5409acbb29258f8e50969fec74a0fdfeeadfeb992f567f4c658a0b0d4 |
|||
stream_145_off00122f42.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x122F42 | 145632 bytes |
SHA-256: f02659d090f97a1243e5e04a03178d7c2d3e8da9624532f9bbb01fc3724ea76e |
|||
stream_147_off0025e3dd.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x25E3DD | 302088 bytes |
SHA-256: ea7fe4486ce258c8dd801883b2b190abab87906cfd7b49082c95f32cd5e42f55 |
|||
stream_152_off0029a771.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x29A771 | 329024 bytes |
SHA-256: a951f504ae32741112a6803d10a4836f120c65342cc9ad8e9f2920af915d28b2 |
|||
stream_157_off002edbaa.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x2EDBAA | 242036 bytes |
SHA-256: 53f05d2ab8f168aaf182f3e91773cfe12e9917f4181f90c4fd3c6e359ba1b455 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.