MALICIOUS
124
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The document exhibits characteristics of a callback phishing or tech-support scam, with a high number of repeated phone numbers and a lure to call for support. The presence of embedded URLs and the document's structure suggest it is part of a larger phishing campaign, likely delivered as a spearphishing attachment. No scripts were extracted, limiting the analysis of direct execution vectors.
Machine Learning
- Nyx PDF Classifier clean score 0.0002
Heuristics 5
-
Travel-support phone-number stuffing scam critical SE_TRAVEL_SUPPORT_PHONE_SCAMDocument repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
Callback phishing phone lure medium SE_CALLBACK_LUREDocument asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) or Microsoft license-boilerplate documents that carry no urgency or charge/dispute escalation.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.sterlingbackcheck.com/Resources/Frequently-Asked-Questions.aspx#collapseSixteen PDF link annotation
- http://www.sterlingvolunteers.com/In PDF document text
- http://www.sterlingbackcheck.com/Resources/Frequently-Asked-Questions.aspx#collapseThirteenIn PDF document text
- https://static.verifiedvolunteers.com/pdf/Volunteer%20Organization%20Admin%20Guide.pdfIn PDF document text
- http://www.sterlingbackcheck.com/Resources/Frequently-Asked-Questions.aspx#collapseFourIn PDF document text
- https://www.sterlingcheck.com/about/privacy/In PDF document text
- http://www.sterlingbackcheck.com/Resources/Frequently-Asked-Questions.aspx#collapseTenIn PDF document text
- https://vimeo.com/111907896In PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://www.microsoft.com/typography/ctfontshttp://lucasfonts.comMicrosoftIn extracted file (stream_014_off000170f7.bin)
- http://en.wikipedia.org/wiki/MIT_LicenseIn extracted file (stream_014_off000170f7.bin)
- http://www.microsoft.com/typography/fonts/default.aspxIn extracted file (stream_014_off000170f7.bin)
- http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0XIn extracted file (stream_014_off000170f7.bin)
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0In extracted file (stream_014_off000170f7.bin)
- http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0aIn extracted file (stream_014_off000170f7.bin)
- http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0In extracted file (stream_014_off000170f7.bin)
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0TIn extracted file (stream_014_off000170f7.bin)
- http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0In extracted file (stream_014_off000170f7.bin)
- http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^In extracted file (stream_014_off000170f7.bin)
- http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0��In extracted file (stream_014_off000170f7.bin)
- http://www.microsoft.com/pkiops/docs/primarycps.htm0@In extracted file (stream_014_off000170f7.bin)
- http://www.microsoft.com/TypographyIn extracted file (stream_014_off000170f7.bin)
- http://www.monotype.com/html/mtname/ms_symbol.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlMicrosoftIn extracted file (font_03_sfnt_off0003cacc.bin)
- http://www.monotype.com/html/type/license.htmlIn extracted file (font_03_sfnt_off0003cacc.bin)
Extracted artifacts 5
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_014_off000170f7.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x170F7 | 162716 bytes |
SHA-256: ed32b45317b3333123ab29b2d5b1859d069f0d75bc9a4e592a612e86ec38a584 |
|||
stream_016_off00027c44.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x27C44 | 125188 bytes |
SHA-256: f125ff41dc83c5903b54c1e01fcb78bd89a4120abc7aeae3096f07a11b00e72b |
|||
font_02_sfnt_off000332f3.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x332F3 | 101652 bytes |
SHA-256: 46f1a13a5e9443a2e56a44da566853fa5002c3d7dcbbf58969e8546f4bff4248 |
|||
font_03_sfnt_off0003cacc.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3CACC | 11088 bytes |
SHA-256: 086b4c456dbe6f09f8c99517bcda6cd0f82646bc0cf77bf0a1e64dd9a7c38fd3 |
|||
font_04_sfnt_off0003e40c.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3E40C | 102668 bytes |
SHA-256: 3796577fc09b69c2ef0a49ff1eb42189fc7fdacb47428ebfe83699b8b0d61555 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.