PDF static analysis report

Static analysis result for SHA-256 f35179729a705c10…

SUSPICIOUS

PDF

715.8 KB Created: 2018-07-16 17:44:54 UTC Authoring application: RAD PDF (via RAD PDF 3.4.6.2 - http://www.radpdf.com) First seen: 2019-05-16
MD5: 53b37aee05027752769df97c6eb5a999 SHA-1: 70a152a5b2648ebe9a33d528a2e06bb12b036398 SHA-256: f35179729a705c102039a33a736e6146e0e2400d3555daaaa20086c21b65a971
44 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0263

Heuristics 4

  • PDF paints image(s) but contains no text operators medium PDF_IMAGE_ONLY_LURE
    PDF has 2 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.radpdf.com In PDF document text
    • http://www.radpdf.com)/Title(Stoltzfusfeed)/Creator(RADIn PDF document text
    • http://www.dynaforms.comIn PDF document text
    • https://www.surveygizmo.com/s3/4472439/Office365PDF link annotation
    • https://www.surveygizmo.com/s3/4474345/Office-365In PDF document text
    • https://www.surveygizmo.com/s3/4475890/MicrosoftIn PDF document text
    • https://www.surveygizmo.com/s3/4476609/Office365In PDF document text
    • https://www.surveygizmo.com/s3/4483440/Office365In PDF document text
    • https://www.surveygizmo.com/s3/4492212/Office365In PDF document text
    • https://www.surveygizmo.com/s3/4495078/Office365In PDF document text
    • https://www.surveygizmo.com/s3/4498876/Office365In PDF document text
    • https://www.surveygizmo.com/s3/4503233/Office365In PDF document text
    • https://www.surveygizmo.com/s3/4503875/Office365In PDF document text
    • https://www.surveygizmo.com/s3/4506513/Office365In PDF document text
    • https://www.surveygizmo.com/s3/4509200/Office365In PDF document text
    • https://www.surveygizmo.com/s3/4511193/Office365In PDF document text
    • https://www.surveygizmo.com/s3/4513395/Office365In PDF document text
    • https://www.surveygizmo.com/s3/4519886/Office365In PDF document text
    • https://www.surveygizmo.com/s3/4520976/Office365In PDF document text
    • https://www.surveygizmo.com/s3/4529709/Office365In PDF document text
    • https://www.surveygizmo.com/s3/4545780/Office365In PDF document text
    • https://www.surveygizmo.com/s3/4548191/Office365In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.iec.chIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_000_off000023a0.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x23A0 4194304 bytes
SHA-256: 0575b3a49af24f2262b117a9f36172b8786380ff525f2f8ae2e2956af0d7b70e
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis found candidate code region(s). Indicators: NOP sled
icc_00_off000af284.icc pdf-icc-profile PDF ICC profile at offset 0xAF284 3144 bytes
SHA-256: 2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e