MALICIOUS
62
Risk Score
Machine Learning
- Nyx PDF Classifier clean score 0.0001
Heuristics 2
-
Travel-support phone-number stuffing scam critical SE_TRAVEL_SUPPORT_PHONE_SCAMDocument repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.microsoft.com/typography/ctfontshttp://fontfabrik.comYou In extracted file (stream_010_off0003412b.bin)
- http://www.microsoft.com/typography/fonts/default.aspxIn extracted file (stream_010_off0003412b.bin)
- http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0XIn extracted file (stream_010_off0003412b.bin)
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0In extracted file (stream_010_off0003412b.bin)
- http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0aIn extracted file (stream_010_off0003412b.bin)
- http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0In extracted file (stream_010_off0003412b.bin)
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0TIn extracted file (stream_010_off0003412b.bin)
- http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0In extracted file (stream_010_off0003412b.bin)
- http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^In extracted file (stream_010_off0003412b.bin)
- http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0��In extracted file (stream_010_off0003412b.bin)
- http://www.microsoft.com/pkiops/docs/primarycps.htm0@In extracted file (stream_010_off0003412b.bin)
- http://www.microsoft.com/TypographyIn extracted file (stream_010_off0003412b.bin)
- https://www.verisign.com/repository/CPS��In extracted file (font_00_sfnt_off0001b7c4.bin)
- https://www.verisign.comIn extracted file (font_00_sfnt_off0001b7c4.bin)
- https://www.verisign.com/repository/verisignlogo.gif06In extracted file (font_00_sfnt_off0001b7c4.bin)
- http://status.verisign.com/class1.crl0In extracted file (font_00_sfnt_off0001b7c4.bin)
- http://www.microsoft.com/typographyIn extracted file (font_00_sfnt_off0001b7c4.bin)
- http://crl.microsoft.com/pki/crl/products/CSPCA.crl0HIn extracted file (font_03_sfnt_off00048587.bin)
- http://www.microsoft.com/pki/certs/CSPCA.crt0In extracted file (font_03_sfnt_off00048587.bin)
- http://crl.microsoft.com/pki/crl/products/tspca.crl0HIn extracted file (font_03_sfnt_off00048587.bin)
- http://www.microsoft.com/pki/certs/tspca.crt0In extracted file (font_03_sfnt_off00048587.bin)
Extracted artifacts 5
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_001_off0000656d.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x656D | 304722 bytes |
SHA-256: 1546bb558f8280fd49a26a5eb6440ae3367cccdc6500f76d65e31a0d707e140d |
|||
stream_010_off0003412b.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x3412B | 177672 bytes |
SHA-256: 817538cafe76a86bb8aec4ced0a93c240c17409eb5b3f0f98318f8a4b1a26f1a |
|||
font_00_sfnt_off0001b7c4.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1B7C4 | 15100 bytes |
SHA-256: 2c75817ffab8663b9529be9bb7316f0fb6e17059357254d2ed5fd0837d2ea884 |
|||
font_01_sfnt_off0001dc43.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1DC43 | 187720 bytes |
SHA-256: b6e578c0757bef231fbbf7c3cb2bbd8ffba676e182941e8abcdaaa854a6e1034 |
|||
font_03_sfnt_off00048587.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x48587 | 39984 bytes |
SHA-256: 42e7928f9e3c4084f6ec37d09cbef43c93b735dacadaac70c3772635c0edd2a4 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.