PDF static analysis report

Static analysis result for SHA-256 7015d778d852dcc1…

CLEAN

PDF

43.8 KB First seen: 2019-03-18
MD5: e1b65e6a91328525fa6ac3ecf6709e96 SHA-1: d60b2635666dddb67b2742b7432128911fd0a061 SHA-256: 7015d778d852dcc11670529d62baa1e9c1c9a82286c272bd7f9f44a3e57caf71
18 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0360

Heuristics 3

  • External URI low PDF_URI
    PDF contains an external URL action
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ladynew.tk/benhorde PDF link annotation
    • https://ladynew.tk/benhorde)endobj8In PDF document text
    • http://www.iec.chIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
icc_00_off0000296b.icc pdf-icc-profile PDF ICC profile at offset 0x296B 4456 bytes
SHA-256: ee2f821d16d12ec9e9f2958ac8865f40912d0ce1fb9625a31b594fab942b1caf
icc_01_off000038db.icc pdf-icc-profile PDF ICC profile at offset 0x38DB 3144 bytes
SHA-256: 2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
font_00_sfnt_off000046b1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x46B1 3788 bytes
SHA-256: 2738fa237e9ab9de27eb576a2be942a29d980f28eedbd0979615d2298a6fc99f
font_01_sfnt_off00005243.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5243 31156 bytes
SHA-256: a62b6ddcd52d6007b7e06a63b5d81c33ba2bf01f9d6ef7681999f862996c2049