PDF static analysis report

Static analysis result for SHA-256 e9a86bf68e33d71f…

CLEAN

PDF

1.60 MB First seen: 2020-07-24
MD5: a558c0b2af58d949a29ce07df30c196b SHA-1: d873750dc966925bf73f41a7c7367c85ae161a13 SHA-256: e9a86bf68e33d71f3cce04e08adc45a13ec402c03a8ebff80b8f1fc47e84ec5f
4 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0001

Heuristics 2

  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.convertapi.com In PDF document text
    • http://www.nationalpcmgp.ca/PDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://crl.microsoft.com/pki/crl/products/CSPCA.crl0HIn PDF document text
    • http://www.microsoft.com/pki/certs/CSPCA.crt0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/tspca.crl0HIn PDF document text
    • http://www.microsoft.com/pki/certs/tspca.crt0In PDF document text
    • http://www.microsoft.com/typographyIn PDF document text
    • https://www.verisign.com/repository/CPS��In PDF document text
    • https://www.verisign.comIn PDF document text
    • https://www.verisign.com/repository/verisignlogo.gif0��In PDF document text
    • https://www.verisign.com/CPS0bIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_042_off00182e09.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x182E09 207844 bytes
SHA-256: 50ec848c6403c79c01b1126d313735bb171f2fffb77b812ce15ce0c744fdeb99
stream_044_off00192134.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x192134 34024 bytes
SHA-256: 9e1be0893ff3ad818074f8c610d64afc2bc26694bc4be9dec94b5fe83e9d28de