PDF static analysis report

Static analysis result for SHA-256 4c132e5a12e295ae…

SUSPICIOUS

PDF

629.3 KB Created: 2010-09-05 07:11:21 +02:00 Authoring application: Adobe InDesign CS5 (7.0) (via Adobe PDF Library 9.9) First seen: 2026-05-08
MD5: 7324839fb09825e2fed0a91759d30c49 SHA-1: 6cac94b6b905c4cf0b86a8fc9e099d3acb3703c4 SHA-256: 4c132e5a12e295ae9cdbb43e479b19d7f887c8665adf01b434e3d00c9bd0a720
44 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a hidden HTML iframe, a common technique for redirecting users to malicious websites. While most embedded URLs are benign, one URL, http://www.ereading.cz/mamu.htm, has an unknown reputation. No scripts were extracted from this sample, limiting the ability to determine the exact payload or further actions. The presence of the hidden iframe and the unknown URL suggest a phishing or redirection attempt.

Machine Learning

  • Nyx PDF Classifier clean score 0.0013

Heuristics 3

  • PDF contains hidden external HTML iframe high PDF_HIDDEN_HTML_IFRAME
    PDF bytes contain a hidden zero-size HTML iframe pointing to an external HTTP(S) URL. This is a strong malicious dropper/redirect indicator and is not expected in ordinary PDF content.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.ereading.cz/mamu.htm In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/g/img/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#In PDF document text
    • http://ns.adobe.com/xap/1.0/t/pg/In PDF document text
    • http://ns.adobe.com/xap/1.0/sType/Dimensions#In PDF document text
    • http://ns.adobe.com/xap/1.0/g/In PDF document text
    • http://ns.adobe.com/illustrator/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/tiff/1.0/In PDF document text
    • http://ns.adobe.com/exif/1.0/In PDF document text
    • http://ns.adobe.com/photoshop/1.0/In PDF document text
    • http://www.apple.com/DTDs/PropertyList-1.0.dtdIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_031_off0004461a.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4461A 13184 bytes
SHA-256: 2aaaef96fba5c93b7d52793cc113f9c6a5701b6767e4972972dde1a6df71e8b0
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.44, consistent with packed or encrypted content.
font_00_cff_off0003e78c.bin pdf-font-stream PDF embedded font (cff) at offset 0x3E78C 6787 bytes
SHA-256: 89378f341e2d8f326848d8885a28648f929d5d0fc3773699337fd37a8ff940d1
font_01_cff_off0003faf6.bin pdf-font-stream PDF embedded font (cff) at offset 0x3FAF6 11635 bytes
SHA-256: 856e5e61b871473b5d52c8b7724e0208258da4671efeaea20aad7fa7c1983914
font_02_cff_off00042125.bin pdf-font-stream PDF embedded font (cff) at offset 0x42125 11759 bytes
SHA-256: 0cb67970ca94fbe686671992700cd9cab3563ca3856b6d4aee1d347d7f586dc1