None of the activity looks hugely out of place for opening a pdf. My advice would be to take a known safe pdf, upload that to virustotal and compare the activity results and see how different they are if at all.
There might be differences based on pdf content so best to try and find a similar pdf (images, urls, etc)
And it’s not the image that’s the attack vector, it’s still a vbscript in an excel document that download the image as its malware payload, decodes the malware and executes it.