Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8265a6532a81700…

MALICIOUS

PDF

6.52 MB
MD5: 2c168fcbb8770b660632d9ce758fc916 SHA-1: 4621ea23b7d287171c42e523331f0487a4e61775 SHA-256: e8265a6532a8170099d481472f060fffb0708e8f948d4d40d213ce97de5d48d3
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The primary heuristic indicates this PDF is a classic advance-fee fraud lure, commonly used in scams involving fake lotteries, inheritances, or parcel deliveries. The document body, though heavily obfuscated, likely contains language consistent with such scams. The high stream count suggests deliberate obfuscation to evade detection.

Heuristics 3

  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Unusually high stream count medium PDF_MANY_STREAMS
    PDF contains 501+ stream objects — may indicate heap spray or heavy obfuscation
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://calibre-ebook.com/xmp-namespace
    • http://ns.adobe.com/xap/1.0/mm/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off00001809.bin
e51a25475d364e94181c69d463c6c6677e0d2cc95f608f264445589a6c90c94f
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1809 10135 bytes
stream_012_off0001421f.bin
dfc598fc1b939872df9065f5e2943ade171340035a788fafd335ff0aae13f3c0
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1421F 13111 bytes
font_00_cff_off000135f8.bin
0689ec1fb3d6292b187685f75266fd655d21e1657f3065310baff2bee2486f30
pdf-font-stream PDF embedded font (cff) at offset 0x135F8 2747 bytes