PDF static analysis report

Static analysis result for SHA-256 902d6221cc0e838c…

SUSPICIOUS

PDF

344.9 KB First seen: 2022-02-20
MD5: d323075e849e54bbadef05bf363090d7 SHA-1: a93717cab162b6369d0b5d74d24502bdd42f8647 SHA-256: 902d6221cc0e838c53e2f5eb230f15d821b4e496c304364366a22b0bce8f373d
44 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1566.002 Spearphishing Link

The primary heuristic indicates this PDF is an advance-fee scam, employing language related to lotteries, parcels, and funds to deceive the user. While several URLs were extracted, they are all confirmed as benign. No scripts were extracted from this sample, limiting further analysis of its behavior. The attack pattern is consistent with social engineering tactics used to solicit funds or personal information.

Machine Learning

  • Nyx PDF Classifier clean score 0.0001

Heuristics 3

  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.un.org/ PDF link annotation
    • https://www.un.org/sg/en/content/profiles/ana-men%C3%A9ndezIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text