SUSPICIOUS
38
Risk Score
Machine Learning
- Nyx PDF Classifier clean score 0.0046
Heuristics 4
-
Clickable URI points to raw IP address medium PDF_URI_IP_LITERALPDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
-
JavaScript action low 1 related finding PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://195.177.94.103/govbr PDF link annotation
Extracted artifacts 8
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0003_000.js |
pdf-javascript-stream | PDF /JS object 3 at offset 0x1C5 | 55 bytes |
SHA-256: 31891b256fb2c725efed8b2bbf38a5e15a3a35b583d76d8b3fb5ee6c8b85f769 |
|||
Preview scriptFirst 1,000 lines of the extracted script
this.print({bUI:true,bSilent:false,bShrinkToFit:true});
|
|||
stream_018_off003aedbb.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x3AEDBB | 51248 bytes |
SHA-256: b7bc956dfea5318a47ab2c77802c0280a72bc8293fcccb146576e553b5f1175e |
|||
icc_00_off0030369f.icc |
pdf-icc-profile | PDF ICC profile at offset 0x30369F | 536 bytes |
SHA-256: d9f822e8083f2f4d1c91e887454be5f75e8c7144b2853408f361e3c4a7a6b36d |
|||
font_00_sfnt_off003aa7a7.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3AA7A7 | 31428 bytes |
SHA-256: 99457c5ccd381a3363602d26f75787eabfe48b31dc0f25ae0e5476ae525db683 |
|||
font_02_sfnt_off003b90cc.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3B90CC | 25220 bytes |
SHA-256: 247899902eb8420c80e1916a676128e0afcadaea1138101269967f3aa161d3cc |
|||
font_03_sfnt_off003bc164.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3BC164 | 35556 bytes |
SHA-256: 541e34d8ef4e89d6a9ea272601f137ab62e0a8a7866a9e440905ed2e72b52054 |
|||
font_04_sfnt_off003c0ae3.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3C0AE3 | 17948 bytes |
SHA-256: 6aa0ffd5d5d8d2a8161f624b6b7048b6f5ec155ee07de2aee85d7c21d7f05091 |
|||
font_05_sfnt_off003c33ce.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3C33CE | 28204 bytes |
SHA-256: d146ad9eb69f0f0d51cbe46e4e58e6835fae71a6defc1b6d0aa1fffcc1fc2f20 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.