PDF static analysis report

Static analysis result for SHA-256 60296fb31c92ccc7…

SUSPICIOUS

PDF

302.6 KB First seen: 2026-07-16
MD5: 66787f5d290ade5fc4855f4c11edda87 SHA-1: 2bb0fd94593daa280b3b0741be5827e5443a5115 SHA-256: 60296fb31c92ccc7dfc5916fc5aa2cd96bb5b36f221844beb2e1fc4d676d43bf
32 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0001

Heuristics 4

  • Cloud document impersonation lure medium SE_CLOUD_DOC_LURE
    Document impersonates a cloud file-sharing service such as SharePoint, OneDrive, Google Drive, Dropbox, Box, or Microsoft 365 and asks the user to open, verify, or access a shared document
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://altgroxxup.reliablestructures.de/OjKmo PDF link annotation

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off00001912.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1912 163200 bytes
SHA-256: 1efe2abf1680333f9886d7239d6a578fa440aa56837b3ee0f6ec7f8a13017520
stream_035_off0002bf59.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2BF59 29288 bytes
SHA-256: a86a03be5de8e2c35c6a34a3f89e94f82c11157a0c681a4e4227d2b786b0aa5b
stream_040_off00038080.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x38080 31900 bytes
SHA-256: 3c4f18b2dacc3cee5f02b418b8b4d1511033bdbcc25982600521fc2ff879e0ff