Malicious PDF — malware analysis report

Static analysis result for SHA-256 0407f26cbb9adfac…

MALICIOUS

PDF

59.41 MB
MD5: 0c8e2528628fba2d0c89801963e2b08e SHA-1: acd27419d6181f7db0b98e6e5fcbe6ef1630f5dc SHA-256: 0407f26cbb9adfac889dfae35a13c2131d633eec0c6cf612caca65e1da576f34
118 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains heuristics indicating it is an advance-fee scam lure, using urgency language to prompt immediate action. Embedded JavaScript and a high stream count suggest obfuscation and potentially malicious code execution. The document body was unreadable, but the heuristics strongly point to a social engineering attack.

Machine Learning

  • Nyx PDF Classifier clean score 0.0004

Heuristics 6

  • JPXDecode + active content — JPEG2000 CVE-family indicator high CVE related PDF_JPX_CVE_2018_4990_RELATED
    PDF uses /JPXDecode (JPEG2000) alongside JavaScript, XFA, or RichMedia indicators. This matches the delivery pattern for Adobe Reader JPEG2000 parser exploit families, including CVE-2018-4990, but does not prove the exact malformed JP2/JPX primitive.
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Unusually high stream count medium PDF_MANY_STREAMS
    PDF contains 501+ stream objects — may indicate heap spray or heavy obfuscation
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://wiki.tripsit.me/wiki/Quick_Guide_to_Volumetric_Dosing
    • http://wiki.tripsit.me/wiki/Drug_combinations
    • http://dxm.tripsit.me
    • https://en.wikipedia.org/wiki/Marquis_reagent
    • https://erowid.org/chemicals/caffeine/caffeine_info1.shtml
    • https://www.bbc.co.uk/news/magazine-
    • http://ns.adobe.com/xap/1.0/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/