PDF static analysis report

Static analysis result for SHA-256 69e02d410aae95c1…

CLEAN

PDF

43.8 KB First seen: 2019-05-31
MD5: 1f204e4cf1ca4ce74cf064db604bfa78 SHA-1: 4d3b46ddf726148afbc61342e27acca87558a537 SHA-256: 69e02d410aae95c18cfab582b408f2837614fe576d8884d9f2b41df50f80650e
18 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0360

Heuristics 3

  • External URI low PDF_URI
    PDF contains an external URL action
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://slightly.cf/benhorde PDF link annotation
    • https://slightly.cf/benhorde)endobj10In PDF document text
    • http://www.iec.chIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
icc_00_off0000296b.icc pdf-icc-profile PDF ICC profile at offset 0x296B 4456 bytes
SHA-256: ee2f821d16d12ec9e9f2958ac8865f40912d0ce1fb9625a31b594fab942b1caf
icc_01_off000038db.icc pdf-icc-profile PDF ICC profile at offset 0x38DB 3144 bytes
SHA-256: 2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
font_00_sfnt_off000047ce.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x47CE 31156 bytes
SHA-256: 4749d2c265d1c3883fce725bd9dfe2a974532008788ec19a0621170cccf82fb1
font_01_sfnt_off0000a23d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA23D 3788 bytes
SHA-256: ba69dba6c6243f4b68ba91ea5821182191331b0dbf3fb2352d5916e4fc1810a0