PDF static analysis report

Static analysis result for SHA-256 f842eba48736e200…

CLEAN

PDF

660.2 KB Created: 2014-09-12 20:12:51 -07:00 Authoring application: Microsoft® Publisher 2010 First seen: 2017-12-24
MD5: 2df543bb8459c6042a550a18c82e8d89 SHA-1: c98497315f7f1c755c15b0f8828f4c3bfebd738d SHA-256: f842eba48736e200096d635515891fc916e6cb5616c0e7a3c916896be6018437
12 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0003

Heuristics 3

  • External URI low PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns# PDF link annotation
    • http://purl.org/dc/elements/1.1/PDF link annotation
    • http://ns.adobe.com/xap/1.0/PDF link annotation
    • http://ns.adobe.com/pdf/1.3/PDF link annotation
    • http://ns.adobe.com/xap/1.0/mm/PDF link annotation
    • http://www.microsoft.com/typography/ctfontshttp://fontfabrik.comYouPDF link annotation
    • http://www.microsoft.com/typography/fonts/default.aspxPDF link annotation
    • http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0XPDF link annotation
    • http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0PDF link annotation
    • http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl0ZPDF link annotation
    • http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0PDF link annotation
    • http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0TPDF link annotation
    • http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0PDF link annotation
    • http://www.microsoft.com/typographyPDF link annotation
    • http://www.microsoft.com/typography/0PDF link annotation

Extracted artifacts 7

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0002de4b.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2DE4B 176924 bytes
SHA-256: 40bf57c169cedbe91e9a9be227bcea958210d9cecb961f24bb79127ece10b761
stream_009_off00059fce.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x59FCE 202852 bytes
SHA-256: a1cc3c18d5b9808f7a8025935bc2b2391216ca4386403577ac9232294e939e80
stream_018_off0007ec1e.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x7EC1E 60073 bytes
SHA-256: ea9c4b078e72d57e833d2d981a5904a2eeaead4bb1e8ba30fd1f06d32be0beea
stream_021_off0008644d.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8644D 2228 bytes
SHA-256: c07a4c58851eeeded7581d110c86870f286e9feaf55cbaf20f81b10ce0c38968
stream_032_off0009f42e.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x9F42E 60073 bytes
SHA-256: de8228137ade8ae7f27f268c7087b5ca1335d121c3a6dbc7ced65aac7bfa9781
font_00_sfnt_off000765c7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x765C7 52069 bytes
SHA-256: 585e963be8115eb993876e3d4f9405d38835682897177972607cf60406969071
font_03_sfnt_off0009744e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9744E 42841 bytes
SHA-256: e67901401c59ded726e3247527050418346a64fc7517c4909c59e060bab924dd