CLEAN
14
Risk Score
Machine Learning
- Nyx PDF Classifier clean score 0.0721
Heuristics 4
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://000za.space/drives/gsign PDF link annotation
- https://app.nihaocloud.com/f/760327f2fe5d49c09609/In PDF document text
- https://app.nihaocloud.com/f/b73b637fa5654e99bb09/In PDF document text
- https://app.nihaocloud.com/f/c0c125acdd274a22bb81/In PDF document text
- https://wirexemailintegration.space/wirexapp.com/home/In PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_014_off00011d84.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x11D84 | 195 bytes |
SHA-256: ca5c42bed4b67d21655df39af61b3d5516c5f54b61604c90d4a5b42955838a3e |
|||
stream_022_off00015ebb.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x15EBB | 195 bytes |
SHA-256: e155de9474d97a7f9353740751230725d9324947127d3d64d5cea87d98c88efd |
|||
stream_034_off0001c04c.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1C04C | 195 bytes |
SHA-256: 10a1143fe49d15a6854d54347db9e11040404fb9229edb0926ea424646ee10e1 |
|||
stream_070_off0002e53c.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x2E53C | 199 bytes |
SHA-256: 71a7ccc500a9da0c6bc2b6b30ef54508959294f6b70eb8e20da04ff6a3517fe9 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.