04 · Forensic analysis
The DOCX is the primary source. The PDF is a derivative with manipulated metadata.
Six forensic disciplines converge on one conclusion: the document was assembled from multiple sources, and the PDF produced to the defense was not the original.
RSID reconstruction
RSIDs (Revision Save Identifiers) are 8-character hex values Word generates on each save. They create a fingerprint of Forensic how a document was assembled. The DOCX contains 61 unique RSIDs across 415 text-run occurrences, revealing 24 distinct writing sessions—far more than the 7 file saves recorded in metadata.
| Layer | RSID | Paragraphs | Content |
|---|---|---|---|
| 1 (Foundation) | 00380012 | 12 | Building target list & “Overall Goal” |
| 2 (Title) | 00A71B6D | 4 | “Storm the Winter Palace” & timeline headers |
| 3 (Ops core) | 00F01E99 | 9 | Covert Sleeper, manpower, team structure |
| 4 (Roles) | 00FC348D | 10 | Recruiter, Covid instructions, preparation |
| 5 (Distract) | 0056613C | 11 | Fire alarms, “we OWN!!” section |
| 6 (Slogans) | 00CC5989 | 4 | “Free and fair elections” chants |
| 7 (Demands) | 00B16F18 | 6 | Paper ballots, election demands |
| 8 (Formatting) | 007864A8 | 17 | Section headers across all pages (rsidRPr=226) |
| 9 (Logistics) | 00A777F7 | 21 | Patriot Plan logistics, building templates |
| 10 (Title late) | 00C730B7 | 1 | “1776 Returns” — late insertion |
Interactive RSID viewer
Three RSID layer visualizations showing the document’s RSID clusters at progressive stages, plus an animated reconstruction.
Figure 1 — Early RSID layer (partial structure)
PDF vs. DOCX: a comparison
Native DOCX
- Author metadata: Eryka Gemma
- Created: Dec 30, 2020, 02:48 UTC
- 24 RSID editing sessions preserved
- Grammarly DocId and SessionId embedded
- Three embedded PNG images + HD Photo
- 125-minute editing window recorded
Rasterized PDF
- No author, creator, or producer metadata
- Created: Feb 8, 2022 (13 months later)
- All RSID and construction history destroyed
- No Grammarly artifacts survive
- 9 JPEG page images at 200 ppi
- ModDate identical to CreationDate (scrubbed)
Object-level PDF findings
Page 7 of the PDF is encoded differently from the other eight pagesForensic:
- Pages 1–6, 8–9: JPEG (
DCTDecode) at 70–152K each - Page 7: Lossless deflate (
FlateDecode) at 289K, withInterpolate=false - Page widths vary: 1344–1346 px (batch 1), 1263 px (page 6), 1277 px (page 7), 1309 px (page 8)
This proves multi-source assembly: at least two different image production methods were used to build this PDF. Page 7 was inserted from a different source or tool.
Font & style analysis
The DOCX uses Forensic only system fonts (no embedded fonts): Arial (79.8% of 746 text runs), Times New Roman (10.2%). The document uses no custom heading styles—231 paragraphs use inline formatting. This is consistent with content pasted from multiple sources and rapidly assembled without document templating.
Image inventory
| Image | Dimensions | Format | Content |
|---|---|---|---|
image1.png | 1280×777 | PNG RGB, 96 ppi | Likely map or header graphic |
image2.png | 750×1000 | PNG RGBA, 96 ppi | Tall portrait orientation |
hdphoto1.wdp | 750×1000 | HD Photo (WDP) | Compressed duplicate of image2.png |
image3.png | 2113×1362 | PNG RGBA, 192 ppi | Retina-class, likely map (page 9) |
No EXIF/GPS data in any image. All are clean PNGs derived from screenshots, not camera originals.