PDF static analysis report

Static analysis result for SHA-256 4843c92d8740bd89…

SUSPICIOUS

PDF

3.07 MB Created: 2019-05-28 11:18:54 +08:00 Authoring application: Microsoft® PowerPoint® 2013 First seen: 2026-05-08
MD5: 838f846b439f3dd7e0634fec2cb1cc29 SHA-1: 85b6a268e3eba3bc6025acb998bfba399ba1a244 SHA-256: 4843c92d8740bd89eddef160c30f294f7cdfa863fa2b96611eff41fe04d40ad0
26 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0001

Heuristics 4

  • TrueType bitmap font + active content — CVE-2023-26369 related info CVE related PDF_CVE_2023_26369_RELATED
    PDF embeds a TrueType font with bitmap tables (EBDT/sbix/CBDT) alongside exploit delivery indicators — CVE-2023-26369 exploits the sfac_GetSbitBitmap function in Adobe's libCoolType for arbitrary code execution. This CVE was actively exploited in the wild, but this rule does not validate the malformed EBLC/EBDT primitive.
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://en.wikipedia.org/wiki/Kd-tree PDF link annotation
    • http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0XIn PDF document text
    • http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0In PDF document text
    • http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0aIn PDF document text
    • http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0TIn PDF document text
    • http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^In PDF document text
    • http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0��In PDF document text
    • http://www.microsoft.com/pkiops/docs/primarycps.htm0@In PDF document text
    • http://www.microsoft.com/TypographyIn PDF document text

Extracted artifacts 16

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_007_off00012166.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x12166 1545264 bytes
SHA-256: b51f569c8acccb9f7f2ea2e52067f37e97012c26541274df849cf89189afdcf8
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis found candidate code region(s). Indicators: heap spray 0x04
stream_008_off00028f3b.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x28F3B 515088 bytes
SHA-256: bd478e81931475c2554875c8c00d3c4c51e5e4768fe689042b67b2bcb148644b
stream_017_off0004dc7c.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4DC7C 145632 bytes
SHA-256: 476e900aaab652cd4cf00a16e38b2ca0a87243e5f170936a3cda54ec90775b0e
stream_024_off000535bc.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x535BC 364818 bytes
SHA-256: dfa3b32ab84f54b509fbdea42315fea7fe9a038243dbb480860f441b20d1e4f8
stream_037_off000ae7e0.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xAE7E0 337512 bytes
SHA-256: 673db5463626e59fb5ba192624b5d48f299f31ebc2e5fa22fc83eeb476373a55
stream_047_off000bd327.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xBD327 337512 bytes
SHA-256: ae16a42009a0d48d4f33bcb59a2c41ebf6563d9e48605d77e87d2f458839c8fe
stream_059_off000d36cc.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xD36CC 145632 bytes
SHA-256: c161c52decf1d68496122a7b1e3063426664264561daaf112cdd54f1962b7a68
stream_063_off000d7833.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xD7833 145632 bytes
SHA-256: b5af173645a50696e9d1b6cced6ff4daac5e7a8b8034d3e97b7770df267a04c6
stream_088_off000f5111.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xF5111 255102 bytes
SHA-256: 404f8607641dfe23fdca64f100818912fe8d8ed256af86b2aa21c3a639b612fe
stream_105_off00101395.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x101395 309960 bytes
SHA-256: df1ab4ca5a66b0e0314c2be587f902d375abfc3183997c84e9e0cee4d33513b6
stream_117_off0010dc4f.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x10DC4F 200490 bytes
SHA-256: 33073847ed43a870c55d0e2a35949808479fbe4e17271e3fe4e5bd6f97befa0d
stream_133_off001165f4.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1165F4 227796 bytes
SHA-256: 2f36f0e5409acbb29258f8e50969fec74a0fdfeeadfeb992f567f4c658a0b0d4
stream_145_off00122f42.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x122F42 145632 bytes
SHA-256: f02659d090f97a1243e5e04a03178d7c2d3e8da9624532f9bbb01fc3724ea76e
stream_147_off0025e3dd.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x25E3DD 302088 bytes
SHA-256: ea7fe4486ce258c8dd801883b2b190abab87906cfd7b49082c95f32cd5e42f55
stream_152_off0029a771.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x29A771 329024 bytes
SHA-256: a951f504ae32741112a6803d10a4836f120c65342cc9ad8e9f2920af915d28b2
stream_157_off002edbaa.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2EDBAA 242036 bytes
SHA-256: 53f05d2ab8f168aaf182f3e91773cfe12e9917f4181f90c4fd3c6e359ba1b455