PDF static analysis report

Static analysis result for SHA-256 7871afa2858e0b27…

SUSPICIOUS

PDF

50.4 KB Created: 2026-05-25 10:50:01 +00:00 Authoring application: Microsoft® Word 2016 (via www.ilovepdf.com) First seen: 2026-06-02
MD5: 42d15a74f71196d015ef9c9bcbcec6e1 SHA-1: 0789a4ed76b8927c6b889dc925440f2d18d83421 SHA-256: 7871afa2858e0b27d50f0e7e0b0a2e7acba3876b0cb0235df2e13bf4e8e7a4fd
32 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0025

Heuristics 4

  • Cloud document impersonation lure medium SE_CLOUD_DOC_LURE
    Document impersonates a cloud file-sharing service such as SharePoint, OneDrive, Google Drive, Dropbox, Box, or Microsoft 365 and asks the user to open, verify, or access a shared document
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://swift-ocean-421.allcompredirectportalshare.workers.dev/ PDF link annotation