CLEAN
4
Risk Score
Machine Learning
- Nyx PDF Classifier clean score 0.0002
Heuristics 2
-
Encrypted PDF (string and stream contents are opaque to static scan) info PDF_ENCRYPTEDPDF declares /Encrypt — string objects and stream contents are encrypted with the standard security handler (RC4 or AES). On its own this is informational; legitimate encrypted documents include signed contracts, billing statements, and rights-managed material. Static heuristics cannot inspect encrypted payload bytes.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0X In PDF document text
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0In PDF document text
- http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl0ZIn PDF document text
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0In PDF document text
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0TIn PDF document text
- http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0In PDF document text
- http://www.microsoft.com/Typography/0In PDF document text
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_014_off00013a8e.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x13A8E | 142268 bytes |
SHA-256: 095b2e8371ffd53942d06fbc23ac6a020d913a445bb9b7b8e481695365bdb09d |
|||
stream_015_off0001cd00.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1CD00 | 144040 bytes |
SHA-256: acf5ed243f230832bdb5a3e3db01c780c28e7a92749cb8aaffdacdc7c1bac1d9 |
|||
stream_016_off00026533.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x26533 | 195456 bytes |
SHA-256: bd6cf80294a9218cbecc8b30e994278343f7777de2bc93f59290970169c469fb |
|||
stream_017_off00033fbf.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x33FBF | 201340 bytes |
SHA-256: 53ef5da9f45b798bbfe1ccc98ba37bd93b736c73a61e26446de40b93b010b17e |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.