Malicious PDF — malware analysis report

Static analysis result for SHA-256 fdd597749201a318…

MALICIOUS

PDF

243.8 KB Created: 2010-06-03 10:16:11 Authoring application: Microsoft® Office Word 2007
MD5: 355d4b0d25b066b80db3960d876116d9 SHA-1: 5f48e5b425c2865d511d5c874574a0be7257fb10 SHA-256: fdd597749201a3187543fb91eb936db86f3b5567ed0844dc4622c54766a52175
72 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The file is a PDF document exhibiting characteristics of an advance-fee scam, specifically mentioning lottery winnings or large sums of money and parcel delivery requirements. While the embedded URLs point to a benign domain, the document's structure strongly suggests a social engineering lure designed to defraud the recipient. No scripts were extracted, limiting the analysis to the document's content and structure.

Machine Learning

  • Nyx PDF Classifier clean score 0.0001

Heuristics 5

  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.fda.gov/ora/compliance_ref/debar/
    • http://www.fda.gov/ora/compliance%5Fref/debar/