PDF static analysis report

Static analysis result for SHA-256 5b25688f73d48d63…

SUSPICIOUS

PDF

1.77 MB Created: 2003-06-16 00:08:57 -03:00 Authoring application: Adobe PageMaker 7.0 (via Acrobat Distiller 5.0 (Windows)) First seen: 2026-05-28
MD5: 84d0a6657b5a8bd320b34efc40c3b62a SHA-1: 5926625e08dd1fc6aa25230f1f7a6de069700f0c SHA-256: 5b25688f73d48d6326bf1dcbc9624ed40f9e832dbbd0be90cd4e1463b0a4f61e
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded URLs that point to various security and hacking-related websites, suggesting a lure to download further content. The 'SE_PASSWORD_ARCHIVE_LURE' heuristic indicates the document is designed to instruct the user to open a password-protected archive, a common tactic to bypass security scanners. The presence of JavaScript streams further suggests potential malicious scripting capabilities.

Machine Learning

  • Nyx PDF Classifier clean score 0.0004

Heuristics 2

  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.visualbooks.com.br In PDF document text
    • http://www.blackcode.comIn PDF document text
    • http://www.hackerslab.org/eorg/fhz/proto.hIn PDF document text
    • http://www.hping.orgIn PDF document text
    • http://packetstormsecurity.orgIn PDF document text
    • http://www.laurentconstantin.comIn PDF document text
    • http://www.oxid.itIn PDF document text
    • http://www.invasao.com.brIn PDF document text
    • http://www.totalsecurity.com.brIn PDF document text
    • http://www.securenet.com.brIn PDF document text
    • http://www.digital-root.comIn PDF document text
    • http://www.anti-trojans.cjb.netIn PDF document text
    • http://www.nmap.orgIn PDF document text
    • http://www.securityfocus.comIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/iX/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
🗂 Part of campaign: hping.org 4 samples

Extracted artifacts 8

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_032_off0006b530.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6B530 163836 bytes
SHA-256: e71fc1263f9f0b5a89199186592540cb2c3863d827a3feb7b66ab86b1f281b94
stream_043_off0008c68e.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8C68E 163836 bytes
SHA-256: db999a66aeadc0c26fdee260a9e32a3c290f47e4dc6038b9ef9357c48a1d94d6
stream_051_off0009cfcc.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x9CFCC 163344 bytes
SHA-256: 78e7f923e7cd39cf3309cf6a39392ef404052b916c91b3f8d527661d85dae47d
stream_052_off000a12b8.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xA12B8 163836 bytes
SHA-256: 7c2ac715f35a31e9fd697e6e91d0647c5c83173a024e2f54350c3d16b1546d45
stream_054_off000a7e50.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0xA7E50 4931 bytes
SHA-256: 0b32d4c14689e1fdbb87f32e19bcd4f6e626a8d8616da76be570c34c224630d2
stream_081_off0011021a.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x11021A 167328 bytes
SHA-256: 694008f160c72b58d7779e649c3d119f8e2987f9265b6e5454a1556048a67bad
stream_137_off0017bae2.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x17BAE2 205176 bytes
SHA-256: 4783f8e0243b4f7c40af941ba467923cdec468fb372b96b635d38d2e2b5e40ba
font_00_sfnt_off001beedb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1BEEDB 4312 bytes
SHA-256: 84ff96c12cb21985dbbfbb8c5aeca615e0fbc93fd78f612f90c346d4c0fe0fb3